Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-50745
Reflected XSS via Unsanitized URL in Revive Adserver Stats Video Script
CVE-2026-50742
A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the affected maintenance tools is not entirely under the attacker's control.
CVE-2026-34916
PHP Code Injection via Unvalidated Delivery Limitations in Revive Adserver
CVE-2023-53931
Revive Adserver 5.4.1 Cross-Site Scripting via Banner Advanced Settings
CVE-2025-52668
Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.
