Revive Adserver
Revive · 23 CVEs
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `c…
Jan 20, 2026
HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php d…
Jan 20, 2026
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script o…
Jan 20, 2026
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver sett…
Jan 20, 2026
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-del…
Jan 20, 2026
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulne…
Dec 2, 2025
Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versio…
Nov 20, 2025
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change oth…
Nov 20, 2025
Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected X…
Nov 20, 2025
Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be…
Nov 20, 2025
Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes…
Nov 20, 2025
Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions ca…
Nov 20, 2025
Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes n…
Nov 20, 2025
Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.
Nov 20, 2025
Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delet…
Nov 20, 2025
Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XS…
Nov 20, 2025
HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box…
Nov 20, 2025
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the usern…
Nov 20, 2025
HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in t…
Nov 20, 2025
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker…
Oct 30, 2025
SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payl…
Oct 30, 2025
A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..
Sep 17, 2023
Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a poten…
May 28, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-21642 | HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserv… | MEDIUM | 0.20% | Jan 20, 2026 |
| CVE-2026-21664 | HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An at… | MEDIUM | 0.20% | Jan 20, 2026 |
| CVE-2026-21663 | HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft… | MEDIUM | 0.20% | Jan 20, 2026 |
| CVE-2026-21640 | HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinatio… | LOW | 0.25% | Jan 20, 2026 |
| CVE-2026-21641 | HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. User… | MEDIUM | 0.27% | Jan 20, 2026 |
| CVE-2025-55129 | HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the… | MEDIUM | 0.24% | Dec 2, 2025 |
| CVE-2025-52668 | Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosu… | MEDIUM | 0.53% | Nov 20, 2025 |
| CVE-2025-48986 | Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy t… | HIGH | 0.62% | Nov 20, 2025 |
| CVE-2025-48987 | Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack. | MEDIUM | 0.51% | Nov 20, 2025 |
| CVE-2025-55123 | Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own a… | MEDIUM | 0.45% | Nov 20, 2025 |
| CVE-2025-52671 | Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information… | MEDIUM | 0.35% | Nov 20, 2025 |
| CVE-2025-52666 | Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable th… | LOW | 0.42% | Nov 20, 2025 |
| CVE-2025-52669 | Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the con… | MEDIUM | 0.29% | Nov 20, 2025 |
| CVE-2025-55124 | Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script. | MEDIUM | 0.41% | Nov 20, 2025 |
| CVE-2025-52670 | Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts | MEDIUM | 0.32% | Nov 20, 2025 |
| CVE-2025-52667 | Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in… | MEDIUM | 0.37% | Nov 20, 2025 |
| CVE-2025-55126 | HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages,… | MEDIUM | 0.21% | Nov 20, 2025 |
| CVE-2025-55127 | HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username wi… | MEDIUM | 0.23% | Nov 20, 2025 |
| CVE-2025-55128 | HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with… | MEDIUM | 0.40% | Nov 20, 2025 |
| CVE-2025-27208 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the us… | MEDIUM | 1.47% | Oct 30, 2025 |
| CVE-2025-52664 | SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users | HIGH | 1.00% | Oct 30, 2025 |
| CVE-2023-38040 | A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions.. | MEDIUM | 2.07% | Sep 17, 2023 |
| CVE-2019-5440 | Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an… | HIGH | 1.58% | May 28, 2019 |
Showing 1 to 23 of 23 CVEs