CVE-2026-50743
- EPSS 0.24%
- Veröffentlicht 20.07.2026 16:53:12
- Zuletzt bearbeitet 23.07.2026 18:27:26
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an att...
CVE-2026-50745
- EPSS 0.32%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:17:24
A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encode...
CVE-2026-50744
- EPSS 0.24%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:19:26
A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session...
CVE-2026-50742
- EPSS 0.28%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:20:29
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected...
CVE-2026-50741
- EPSS 4.46%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:21:29
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeti...
CVE-2026-50740
- EPSS 0.32%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 08.07.2026 20:16:51
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.
CVE-2026-50739
- EPSS 0.39%
- Veröffentlicht 26.06.2026 01:11:14
- Zuletzt bearbeitet 29.06.2026 20:22:51
A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7 and earlier. As a result, a l...
CVE-2026-44959
- EPSS 0.47%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 23.06.2026 18:17:52
A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which...
CVE-2026-34912
- EPSS 0.24%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 23.06.2026 18:17:43
A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by o...
CVE-2026-34913
- EPSS 0.24%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 23.06.2026 18:17:43
A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same ...