CVE-2026-34914
- EPSS 0.31%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 23.06.2026 18:17:43
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensur...
CVE-2026-34915
- EPSS 0.23%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 23.06.2026 18:17:43
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved ...
CVE-2026-34917
- EPSS 0.32%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 25.06.2026 19:52:36
Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabi...
- EPSS 0.34%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 25.06.2026 19:52:36
Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through us...
CVE-2026-44957
- EPSS 0.24%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 23.06.2026 18:17:51
A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, leading to inconsistent ownership relationships. This...
CVE-2026-44958
- EPSS 0.27%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 23.06.2026 18:17:51
An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten sole...
- EPSS 0.34%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 25.06.2026 19:52:36
A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log details for affected entries, any malicious JavaScript payload embedded in the username would be executed due to missing output san...
- EPSS 0.34%
- Veröffentlicht 23.06.2026 16:14:38
- Zuletzt bearbeitet 25.06.2026 19:52:36
The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.
CVE-2026-21642
- EPSS 0.17%
- Veröffentlicht 20.01.2026 20:48:48
- Zuletzt bearbeitet 30.01.2026 20:14:51
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a...
CVE-2026-21663
- EPSS 0.17%
- Veröffentlicht 20.01.2026 20:48:47
- Zuletzt bearbeitet 03.02.2026 21:05:31
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator ...