Adserver
Revive · 18 CVEs
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or…
Jul 20, 2026
A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script…
Jun 26, 2026
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and e…
Jun 26, 2026
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Rev…
Jun 26, 2026
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix…
Jun 26, 2026
A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation…
Jun 26, 2026
A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login m…
Jun 26, 2026
A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Ad…
Jun 23, 2026
Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication…
Jun 23, 2026
Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑gene…
Jun 23, 2026
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privile…
Jun 23, 2026
An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 an…
Jun 23, 2026
The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users…
Jun 23, 2026
A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log…
Jun 23, 2026
A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and ear…
Jun 23, 2026
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Reviv…
Jun 23, 2026
A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑…
Jun 23, 2026
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a…
Jun 23, 2026
The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this…
Apr 14, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-50743 | A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered v… | MEDIUM | 0.14% | Jul 20, 2026 |
| CVE-2026-50745 | A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best pra… | MEDIUM | 0.38% | Jun 26, 2026 |
| CVE-2026-50740 | A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could expl… | MEDIUM | 0.38% | Jun 26, 2026 |
| CVE-2026-50742 | A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused… | MEDIUM | 0.34% | Jun 26, 2026 |
| CVE-2026-50741 | Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a dis… | HIGH | 4.94% | Jun 26, 2026 |
| CVE-2026-50739 | A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers throug… | MEDIUM | 0.49% | Jun 26, 2026 |
| CVE-2026-50744 | A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in th… | MEDIUM | 0.29% | Jun 26, 2026 |
| CVE-2026-34913 | A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a l… | MEDIUM | 0.27% | Jun 23, 2026 |
| CVE-2026-34917 | Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users.… | MEDIUM | 0.38% | Jun 23, 2026 |
| CVE-2026-44956 | Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in… | n/a | 0.39% | Jun 23, 2026 |
| CVE-2026-34914 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid para… | HIGH | 0.39% | Jun 23, 2026 |
| CVE-2026-44958 | An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions we… | MEDIUM | 0.34% | Jun 23, 2026 |
| CVE-2026-44961 | The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled imp… | n/a | 0.41% | Jun 23, 2026 |
| CVE-2026-44960 | A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log details for affected entries, any malici… | n/a | 0.39% | Jun 23, 2026 |
| CVE-2026-44957 | A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be rea… | MEDIUM | 0.27% | Jun 23, 2026 |
| CVE-2026-34912 | A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its… | MEDIUM | 0.27% | Jun 23, 2026 |
| CVE-2026-44959 | A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected… | HIGH | 0.58% | Jun 23, 2026 |
| CVE-2026-34915 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clien… | MEDIUM | 0.26% | Jun 23, 2026 |
| CVE-2023-26756 | The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits… | HIGH | 1.15% | Apr 14, 2023 |
Showing 1 to 18 of 18 CVEs