Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-50743
A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.
CVE-2026-50745
Reflected XSS via Unsanitized URL in Revive Adserver Stats Video Script
CVE-2026-50740
Reflected XSS via zone‑include.php Refresh Parameter in Revive Adserver 6.0.7 and Earlier
CVE-2026-50742
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the affected maintenance tools is not entirely under the attacker's control.
CVE-2026-50741
Plugin Identifier Injection Bypass in Revive Adserver
