Revive adserver
This hub aggregates every CVE we track for Revive adserver, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
77
CVEs tracked
5
Critical
13
High
0
In CISA KEV
Severity distribution
MEDIUM55HIGH13CRITICAL5LOW4
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
2
13
2
5
0
0
0
0
7
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Revive adserver.
- CVE-2026-50739A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` scri...4.3
- CVE-2026-50744A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the m...4.3
- CVE-2026-50742A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed witho...5.4
- CVE-2026-50740A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFr...5.4
- CVE-2026-50745A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty c...6.1
- CVE-2026-50741Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin ide...8.8
- CVE-2026-34916A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP cod...8.8
- CVE-2026-21642HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific U...6.1
- CVE-2026-21664HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that i...6.1
- CVE-2026-21641HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers ...6.5
- CVE-2026-21640HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin us...2.7
- CVE-2026-21663HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML ...6.1
- CVE-2023-53931Revive Adserver 5.4.1 Cross-Site Scripting via Banner Advanced Settings6.1
- CVE-2025-55129HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several a...5.4
- CVE-2025-52668Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored ...5.4
Product normalization is registry-driven with AI assist and human review. How it works