Adserver

Revive · 18 CVEs

CVE-2026-50743
MEDIUM

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or…

Jul 20, 2026

CVE-2026-50745
MEDIUM

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script…

Jun 26, 2026

CVE-2026-50740
MEDIUM

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and e…

Jun 26, 2026

CVE-2026-50742
MEDIUM

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Rev…

Jun 26, 2026

CVE-2026-50741
HIGH

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix…

Jun 26, 2026

CVE-2026-50739
MEDIUM

A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation…

Jun 26, 2026

CVE-2026-50744
MEDIUM

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login m…

Jun 26, 2026

CVE-2026-34913
MEDIUM

A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Ad…

Jun 23, 2026

CVE-2026-34917
MEDIUM

Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication…

Jun 23, 2026

CVE-2026-44956

Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑gene…

Jun 23, 2026

CVE-2026-34914
HIGH

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privile…

Jun 23, 2026

CVE-2026-44958
MEDIUM

An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 an…

Jun 23, 2026

CVE-2026-44961

The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users…

Jun 23, 2026

CVE-2026-44960

A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log…

Jun 23, 2026

CVE-2026-44957
MEDIUM

A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and ear…

Jun 23, 2026

CVE-2026-34912
MEDIUM

A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Reviv…

Jun 23, 2026

CVE-2026-44959
HIGH

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑…

Jun 23, 2026

CVE-2026-34915
MEDIUM

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a…

Jun 23, 2026

CVE-2023-26756
HIGH

The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this…

Apr 14, 2023

Showing 1 to 18 of 18 CVEs