VYPR

Adserver

by Revive Adserver

Source repositories

CVEs (86)

  • CVE-2026-21664MedJan 20, 2026
    risk 0.40cvss 6.1epss 0.00

    HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the…

  • CVE-2026-21663MedJan 20, 2026
    risk 0.40cvss 6.1epss 0.00

    HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is…

  • CVE-2026-21642MedJan 20, 2026
    risk 0.40cvss 6.1epss 0.00

    HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator…

  • CVE-2023-53931MedDec 17, 2025
    risk 0.40cvss 6.1epss 0.02

    Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a malicious link to the banner-advanced.php endpoint with XSS payloads in prepend and append…

  • CVE-2025-55124MedNov 20, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

  • CVE-2025-48987MedNov 20, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

  • CVE-2023-38040MedSep 17, 2023
    risk 0.40cvss 6.1epss 0.02

    A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..

  • CVE-2020-8115MedFeb 4, 2020
    risk 0.40cvss 6.1epss 0.07

    A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an http-only cookie as of…

  • CVE-2017-5833MedMar 3, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

  • CVE-2017-5831MedMar 3, 2017
    risk 0.38cvss 5.9epss 0.01

    Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.

  • CVE-2025-55129MedDec 2, 2025
    risk 0.35cvss 5.4epss 0.00

    HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation has been independently…

  • CVE-2025-55123MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

  • CVE-2025-52668MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.01

    Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

  • CVE-2025-52667MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

  • CVE-2025-55127MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.00

    HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username…

  • CVE-2019-5433MedMay 6, 2019
    risk 0.35cvss 5.4epss 0.02

    A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks.…

  • CVE-2016-9472MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.02

    Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other parameters. It has to be noted that the window for such attack vectors to be possible…

  • CVE-2016-9457MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.02

    Revive Adserver before 3.2.3 suffers from Reflected XSS. `www/admin/stats.php` is vulnerable to reflected XSS attacks via multiple parameters that are not properly sanitised or escaped when displayed, such as setPerPage, pageId, bannerid, period_start, period_end, and possibly…

  • CVE-2016-9454MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the…

  • CVE-2016-9130MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn't properly escaped when displayed in the campaign-zone.php script.

Page 2 of 5