VYPR

Adserver

by Revive Adserver

Source repositories

CVEs (86)

  • CVE-2026-50740MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.

  • CVE-2026-50739MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7 and earlier. As a result, a low‑privileged user…

  • CVE-2026-44959HigJun 23, 2026
    risk 0.00cvss 8.8epss 0.00

    A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed…

  • CVE-2026-44958MedJun 23, 2026
    risk 0.00cvss 5.4epss 0.00

    An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten solely based on banner edit…

  • CVE-2026-44957MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, leading to inconsistent ownership relationships. This issue was exploitable only…

  • CVE-2026-34916HigJun 23, 2026
    risk 0.00cvss 8.8epss 0.01

    A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during…

  • CVE-2026-34915MedJun 23, 2026
    risk 0.00cvss 6.1epss 0.00

    A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all…

  • CVE-2026-34914HigJun 23, 2026
    risk 0.00cvss 8.3epss 0.00

    A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters…

  • CVE-2026-34913MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in…

  • CVE-2026-34912MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same…

  • CVE-2021-22872MedJan 26, 2021
    risk 0.00cvss 6.1epss 0.03

    Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not…

  • CVE-2021-22871MedJan 26, 2021
    risk 0.00cvss 4.8epss 0.02

    Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS)…

  • CVE-2015-7373Oct 14, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in a banner.

  • CVE-2015-7372Oct 14, 2015
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the layerstyle parameter.

  • CVE-2015-7371Oct 14, 2015
    risk 0.00cvss epss 0.03

    Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct request.

  • CVE-2015-7370Oct 14, 2015
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds plugin in Revive Adserver before 3.2.2 and CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2…

  • CVE-2015-7369Oct 14, 2015
    risk 0.00cvss epss 0.03

    The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.

  • CVE-2015-7368Oct 14, 2015
    risk 0.00cvss epss 0.01

    Revive Adserver before 3.2.2 does not send the appropriate Cache-Control HTTP headers in responses for admin UI pages, which allows local users to obtain sensitive information via the web browser cache.

  • CVE-2015-7367Oct 14, 2015
    risk 0.00cvss epss 0.03

    Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked.

  • CVE-2015-7366Oct 14, 2015
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authentication of users for requests that (1) perform certain plugin actions and possibly cause a denial of service (disabled core plugins) via unknown…

Page 4 of 5