Revive Adserver

Revive · 23 CVEs

CVE-2026-21642
MEDIUM

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `c…

Jan 20, 2026

CVE-2026-21664
MEDIUM

HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php d…

Jan 20, 2026

CVE-2026-21663
MEDIUM

HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script o…

Jan 20, 2026

CVE-2026-21640
LOW

HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver sett…

Jan 20, 2026

CVE-2026-21641
MEDIUM

HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-del…

Jan 20, 2026

CVE-2025-55129
MEDIUM

HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulne…

Dec 2, 2025

CVE-2025-52668
MEDIUM

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versio…

Nov 20, 2025

CVE-2025-48986
HIGH

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change oth…

Nov 20, 2025

CVE-2025-48987
MEDIUM

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected X…

Nov 20, 2025

CVE-2025-55123
MEDIUM

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be…

Nov 20, 2025

CVE-2025-52671
MEDIUM

Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes…

Nov 20, 2025

CVE-2025-52666
LOW

Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions ca…

Nov 20, 2025

CVE-2025-52669
MEDIUM

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes n…

Nov 20, 2025

CVE-2025-55124
MEDIUM

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

Nov 20, 2025

CVE-2025-52670
MEDIUM

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delet…

Nov 20, 2025

CVE-2025-52667
MEDIUM

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XS…

Nov 20, 2025

CVE-2025-55126
MEDIUM

HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box…

Nov 20, 2025

CVE-2025-55127
MEDIUM

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the usern…

Nov 20, 2025

CVE-2025-55128
MEDIUM

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in t…

Nov 20, 2025

CVE-2025-27208
MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker…

Oct 30, 2025

CVE-2025-52664
HIGH

SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payl…

Oct 30, 2025

CVE-2023-38040
MEDIUM

A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..

Sep 17, 2023

CVE-2019-5440
HIGH

Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a poten…

May 28, 2019

Showing 1 to 23 of 23 CVEs