Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Revive Adserver HIGH 8.8
CVE-2026-50741

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sen…

Fix: 6.0.8+
Fix from $1,950 2026-06-26
Revive Adserver MEDIUM 6.1
CVE-2026-50745

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follo…

Fix: 6.0.8+
Fix from $1,600 2026-06-26
Revive Adserver MEDIUM 5.4
CVE-2026-50740

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user …

Fix: 6.0.8+
Fix from $1,600 2026-06-26
Revive Adserver MEDIUM 5.4
CVE-2026-50742

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue …

Fix: 6.0.8+
Fix from $1,600 2026-06-26
Revive Adserver MEDIUM 6.1
CVE-2023-53931

Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicio…

No fix yet
Fix from $1,600 2025-12-17
Revive Adserver MEDIUM 6.5
CVE-2025-52670

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accou…

Fix: after 6.0.1
Fix from $1,600 2025-11-20
Revive Adserver MEDIUM 6.1
CVE-2025-55124

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

Fix: after 6.0.1
Fix from $1,600 2025-11-20
Revive Adserver MEDIUM 5.4
CVE-2025-55123

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to t…

No fix yet
Fix from $1,600 2025-11-20
Revive Adserver HIGH 8.8
CVE-2025-48986

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and po…

Fix: after 6.0.1
Fix from $1,950 2025-11-20
Revive Adserver MEDIUM 6.1
CVE-2025-48987

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

Fix: after 6.0.1
Fix from $1,600 2025-11-20
Revive Adserver MEDIUM 5.4
CVE-2025-52667

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a …

Fix: after 6.0.1
Fix from $1,600 2025-11-20
Revive Adserver MEDIUM 5.4
CVE-2025-52668

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential informatio…

Fix: after 6.0.1
Fix from $1,600 2025-11-20
Revive Adserver HIGH 8.8
CVE-2025-52664

SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in use…

Patch available
Fix from $1,950 2025-10-31
Revive Adserver MEDIUM 6.1
CVE-2025-27208

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access…

Fix: 6.0.0+
Fix from $1,600 2025-10-31
Revive Adserver MEDIUM 6.1
CVE-2023-38040

A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..

Fix: after 5.4.1
Fix from $1,600 2023-09-17
Revive Adserver HIGH 7.1
CVE-2021-22948

Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some …

Fix: 5.3.0+
Fix from $1,950 2021-09-23
Revive Adserver MEDIUM 6.1
CVE-2021-22888EPSS 20%

Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could …

Fix: 5.2.0+
Fix from $1,600 2021-03-25
Revive Adserver MEDIUM 6.1
CVE-2021-22889EPSS 36%

Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scrip…

Fix: 5.2.0+
Fix from $1,600 2021-03-25
Revive Adserver MEDIUM 6.1
CVE-2021-22874EPSS 18%

Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.

Fix: 5.1.1+
Fix from $1,600 2021-01-28
Revive Adserver MEDIUM 6.1
CVE-2021-22875EPSS 18%

Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.

Fix: 5.1.1+
Fix from $1,600 2021-01-28
Revive Adserver MEDIUM 6.1
CVE-2021-22872

Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery scrip…

Fix: 5.1.0+
Fix from $1,600 2021-01-26
Revive Adserver MEDIUM 6.1
CVE-2021-22873EPSS 70%

Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scri…

Fix: 5.1.0+
Fix from $1,600 2021-01-26
Revive Adserver MEDIUM 6.8
CVE-2020-8142

A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like…

Fix: 5.0.5+
Fix from $1,600 2020-04-03
Revive Adserver MEDIUM 6.1
CVE-2020-8143EPSS 70%

An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could tr…

Fix: 5.0.5+
Fix from $1,600 2020-04-03
Revive Adserver MEDIUM 6.1
CVE-2020-8115EPSS 7%

A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. T…

Fix: after 5.0.3
Fix from $1,600 2020-02-04
Revive Adserver HIGH 8.1
CVE-2019-5440

Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass att…

Fix: 4.2.1+
Fix from $1,950 2019-05-28
Revive Adserver MEDIUM 5.4
CVE-2019-5433

A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL th…

Fix: 4.2.0+
Fix from $1,600 2019-05-06
Revive Adserver CRITICAL 9.0
CVE-2016-9470

Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected F…

Fix: after 3.2.4
Fix from $2,300 2017-03-28
Revive Adserver MEDIUM 5.4
CVE-2016-9472

Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attac…

Fix: after 3.2.4
Fix from $1,600 2017-03-28
Revive Adserver CRITICAL 9.8
CVE-2016-9124

Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable …

Fix: after 3.2.2
Fix from $2,300 2017-03-28