CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Revive Remove filter Clear all
CVE-2026-50743 MEDIUM

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered v…

CVSS 5.4 EPSS 0.14% Jul 20, 2026
CVE-2026-50745 MEDIUM

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best pra…

CVSS 6.1 EPSS 0.38% Jun 26, 2026
CVE-2026-50740 MEDIUM

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could expl…

CVSS 5.4 EPSS 0.38% Jun 26, 2026
CVE-2026-50742 MEDIUM

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused…

CVSS 5.4 EPSS 0.34% Jun 26, 2026
CVE-2026-50741 HIGH

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a dis…

CVSS 8.8 EPSS 4.94% Jun 26, 2026
CVE-2026-50739 MEDIUM

A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers throug…

CVSS 4.3 EPSS 0.49% Jun 26, 2026
CVE-2026-50744 MEDIUM

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in th…

CVSS 4.3 EPSS 0.29% Jun 26, 2026
CVE-2026-34913 MEDIUM

A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a l…

CVSS 4.3 EPSS 0.27% Jun 23, 2026
CVE-2026-34917 MEDIUM

Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users.…

CVSS 4.3 EPSS 0.38% Jun 23, 2026
CVE-2026-44956

Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in…

CVSS n/a EPSS 0.39% Jun 23, 2026
CVE-2026-34914 HIGH

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid para…

CVSS 8.3 EPSS 0.39% Jun 23, 2026
CVE-2026-44958 MEDIUM

An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions we…

CVSS 5.4 EPSS 0.34% Jun 23, 2026
CVE-2026-44961

The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled imp…

CVSS n/a EPSS 0.41% Jun 23, 2026
CVE-2026-44960

A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log details for affected entries, any malici…

CVSS n/a EPSS 0.39% Jun 23, 2026
CVE-2026-44957 MEDIUM

A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be rea…

CVSS 4.3 EPSS 0.27% Jun 23, 2026
CVE-2026-34912 MEDIUM

A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its…

CVSS 4.3 EPSS 0.27% Jun 23, 2026
CVE-2026-44959 HIGH

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected…

CVSS 8.8 EPSS 0.58% Jun 23, 2026
CVE-2026-34915 MEDIUM

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clien…

CVSS 6.1 EPSS 0.26% Jun 23, 2026
CVE-2026-21642 MEDIUM

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserv…

CVSS 6.1 EPSS 0.20% Jan 20, 2026
CVE-2026-21664 MEDIUM

HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An at…

CVSS 6.1 EPSS 0.20% Jan 20, 2026
CVE-2026-21663 MEDIUM

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft…

CVSS 6.1 EPSS 0.20% Jan 20, 2026
CVE-2026-21640 LOW

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinatio…

CVSS 2.7 EPSS 0.25% Jan 20, 2026
CVE-2026-21641 MEDIUM

HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. User…

CVSS 6.5 EPSS 0.27% Jan 20, 2026
CVE-2025-55129 MEDIUM

HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the…

CVSS 5.4 EPSS 0.24% Dec 2, 2025
CVE-2025-52668 MEDIUM

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosu…

CVSS 5.4 EPSS 0.53% Nov 20, 2025

Showing 1 to 25 CVEs · page 1 (more available)