VYPR

Vendor CVEs

Revive Adserver

All CVEs

87 total · sorted by risk
  • CVE-2019-5434CriMay 6, 2019
    risk 0.71cvss 9.8epss 0.57

    An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related…

  • CVE-2016-9125CriMar 28, 2017
    risk 0.64cvss 9.8epss 0.03

    Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for…

  • CVE-2016-9124CriMar 28, 2017
    risk 0.64cvss 9.8epss 0.02

    Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable to password-guessing attacks. An account lockdown feature was considered, but rejected to avoid introducing service disruptions to…

  • CVE-2017-5830CriMar 3, 2017
    risk 0.64cvss 9.8epss 0.03

    Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.

  • CVE-2016-9470CriMar 28, 2017
    risk 0.59cvss 9.0epss 0.02

    Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually…

  • CVE-2025-48986HigNov 20, 2025
    risk 0.57cvss 8.8epss 0.01

    Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

  • CVE-2016-9456HigMar 28, 2017
    risk 0.57cvss 8.8epss 0.01

    Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The Revive Adserver team conducted a security audit of the admin interface scripts in order to identify and fix other potential CSRF vulnerabilities. Over 20+ such issues were fixed.

  • CVE-2016-9455HigMar 28, 2017
    risk 0.57cvss 8.8epss 0.01

    Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/banner-advanced.php`,…

  • CVE-2016-9127HigMar 28, 2017
    risk 0.57cvss 8.8epss 0.01

    Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). The password recovery form in Revive Adserver is vulnerable to CSRF attacks. This vulnerability could be exploited to send a large number of password recovery emails to the registered users, especially…

  • CVE-2019-5440HigMay 28, 2019
    risk 0.53cvss 8.1epss 0.02

    Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication bypass attack if an attacker exploits the password recovery functionality. In lib/OA/Dal/PasswordRecovery.php, the function…

  • CVE-2025-52664HigOct 31, 2025
    risk 0.50cvss 8.8epss 0.01

    SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users

  • CVE-2023-26756HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits and password-quality features.

  • CVE-2022-4680HigJan 30, 2023
    risk 0.47cvss 7.2epss 0.01

    The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

  • CVE-2021-22948HigSep 23, 2021
    risk 0.46cvss 7.1epss 0.03

    Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function. Under some circumstances, an attacker could theoretically be able to brute force session IDs in order to take over a specific account.

  • CVE-2021-22873MedJan 26, 2021
    risk 0.45cvss 6.1epss 0.70

    Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had previously been available by design to allow third party ad servers to track such metrics when…

  • CVE-2020-8143MedApr 3, 2020
    risk 0.45cvss 6.1epss 0.70

    An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the…

  • CVE-2020-8142MedApr 3, 2020
    risk 0.44cvss 6.8epss 0.01

    A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in user to type the current password in order to change the e-mail address or the…

  • CVE-2026-21641MedJan 20, 2026
    risk 0.42cvss 6.5epss 0.00

    HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed to delete trackers owned by other accounts.

  • CVE-2025-52670MedNov 20, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

  • CVE-2025-55128MedNov 20, 2025
    risk 0.42cvss 6.5epss 0.00

    HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a…

  • CVE-2025-55126MedNov 20, 2025
    risk 0.42cvss 6.5epss 0.00

    HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for the stored XSS

  • CVE-2026-21664MedJan 20, 2026
    risk 0.40cvss 6.1epss 0.00

    HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the…

  • CVE-2026-21663MedJan 20, 2026
    risk 0.40cvss 6.1epss 0.00

    HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator visits the URL, the HTML is…

  • CVE-2026-21642MedJan 20, 2026
    risk 0.40cvss 6.1epss 0.00

    HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a parameter. If a logged in administrator…

  • CVE-2023-53931MedDec 17, 2025
    risk 0.40cvss 6.1epss 0.03

    Revive Adserver 5.4.1 contains a cross-site scripting vulnerability in the banner advanced configuration page that allows attackers to inject malicious scripts. Attackers can craft a malicious link to the banner-advanced.php endpoint with XSS payloads in prepend and append…

  • CVE-2025-55124MedNov 20, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

  • CVE-2025-48987MedNov 20, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

  • CVE-2023-38040MedSep 17, 2023
    risk 0.40cvss 6.1epss 0.02

    A reflected XSS vulnerability exists in Revive Adserver 5.4.1 and earlier versions..

  • CVE-2020-8115MedFeb 4, 2020
    risk 0.40cvss 6.1epss 0.07

    A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exploits: the session identifier cannot be accessed as it is stored in an http-only cookie as of…

  • CVE-2017-5833MedMar 3, 2017
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

  • CVE-2017-5831MedMar 3, 2017
    risk 0.38cvss 5.9epss 0.01

    Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.

  • CVE-2025-55129MedDec 2, 2025
    risk 0.35cvss 5.4epss 0.00

    HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques. Homoglyphs based impersonation has been independently…

  • CVE-2025-55123MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

  • CVE-2025-52668MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.01

    Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

  • CVE-2025-52667MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

  • CVE-2025-55127MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.00

    HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually indistinguishable from its legitimate counterpart when the username…

  • CVE-2019-5433MedMay 6, 2019
    risk 0.35cvss 5.4epss 0.02

    A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks.…

  • CVE-2016-9472MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.02

    Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other parameters. It has to be noted that the window for such attack vectors to be possible…

  • CVE-2016-9457MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.02

    Revive Adserver before 3.2.3 suffers from Reflected XSS. `www/admin/stats.php` is vulnerable to reflected XSS attacks via multiple parameters that are not properly sanitised or escaped when displayed, such as setPerPage, pageId, bannerid, period_start, period_end, and possibly…

  • CVE-2016-9454MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The banner image URL for external banners wasn't properly escaped when displayed in most of the…

  • CVE-2016-9130MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn't properly escaped when displayed in the campaign-zone.php script.

  • CVE-2016-9129MedMar 28, 2017
    risk 0.35cvss 5.3epss 0.01

    Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery…

  • CVE-2016-9128MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.02

    Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to steal the session ID of an authenticated user, by tricking them into visiting a…

  • CVE-2016-9126MedMar 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user with enough privileges to create other users could exploit…

  • CVE-2017-5832MedMar 3, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.

  • CVE-2025-27208MedOct 31, 2025
    risk 0.33cvss 6.1epss 0.01

    A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript…

  • CVE-2025-52671MedNov 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.

  • CVE-2025-52669MedNov 20, 2025
    risk 0.28cvss 4.3epss 0.00

    Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

  • CVE-2016-9471LowMar 28, 2017
    risk 0.20cvss 3.1epss 0.01

    Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when creating users on a Revive Adserver instance. Especially, control characters were not filtered, allowing apparently identical usernames to co-exist in the…

  • CVE-2026-21640LowJan 20, 2026
    risk 0.18cvss 2.7epss 0.00

    HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be disabled due to a fatal PHP error.

Page 1 of 2