CVE-2025-52668
- EPSS 0.53%
- Veröffentlicht 20.11.2025 19:11:36
- Zuletzt bearbeitet 02.12.2025 20:19:57
Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.
CVE-2025-52670
- EPSS 0.32%
- Veröffentlicht 20.11.2025 19:10:15
- Zuletzt bearbeitet 02.12.2025 20:17:35
Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts
CVE-2025-52669
- EPSS 0.29%
- Veröffentlicht 20.11.2025 19:10:15
- Zuletzt bearbeitet 02.12.2025 20:19:15
Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.
CVE-2025-55123
- EPSS 0.45%
- Veröffentlicht 20.11.2025 19:10:15
- Zuletzt bearbeitet 05.12.2025 20:17:35
Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.
CVE-2025-52667
- EPSS 0.37%
- Veröffentlicht 20.11.2025 19:10:15
- Zuletzt bearbeitet 02.12.2025 20:24:38
Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.
CVE-2025-52666
- EPSS 0.42%
- Veröffentlicht 20.11.2025 19:10:15
- Zuletzt bearbeitet 02.12.2025 20:31:30
Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.
CVE-2025-52671
- EPSS 0.35%
- Veröffentlicht 20.11.2025 19:10:15
- Zuletzt bearbeitet 02.12.2025 20:05:41
Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.
CVE-2025-55124
- EPSS 0.42%
- Veröffentlicht 20.11.2025 19:10:15
- Zuletzt bearbeitet 26.11.2025 16:56:10
Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.
CVE-2025-27208
- EPSS 1.35%
- Veröffentlicht 30.10.2025 23:32:11
- Zuletzt bearbeitet 01.12.2025 20:15:50
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and ...
CVE-2025-52664
- EPSS 0.92%
- Veröffentlicht 30.10.2025 23:29:22
- Zuletzt bearbeitet 01.12.2025 20:15:51
SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users