CVE-2026-50745
- EPSS 0.32%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:17:24
A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encode...
CVE-2026-50744
- EPSS 0.24%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:19:26
A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session...
CVE-2026-50742
- EPSS 0.28%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:20:29
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected...
CVE-2026-50741
- EPSS 4.46%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:21:29
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeti...
CVE-2026-50740
- EPSS 0.32%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 08.07.2026 20:16:51
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.
CVE-2026-50739
- EPSS 0.39%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:22:51
A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7 and earlier. As a result, a l...
CVE-2026-34916
- EPSS 0.75%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 23.06.2026 18:17:43
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database an...
CVE-2023-53931
- EPSS 2.69%
- Veröffentlicht 17.12.2025 22:44:58
- Zuletzt bearbeitet 27.12.2025 17:15:44
Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a malicious link to the banner-advanced.php endpoint with XSS payload...
CVE-2025-48987
- EPSS 0.51%
- Veröffentlicht 20.11.2025 19:11:36
- Zuletzt bearbeitet 25.11.2025 18:56:45
Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.
CVE-2025-48986
- EPSS 0.62%
- Veröffentlicht 20.11.2025 19:11:36
- Zuletzt bearbeitet 25.11.2025 18:57:29
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.