VYPR

Vendor CVEs

Revive Adserver

All CVEs

87 total · sorted by risk
  • CVE-2025-52666LowNov 20, 2025
    risk 0.18cvss 2.7epss 0.00

    Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.

  • CVE-2021-22889MedMar 25, 2021
    risk 0.03cvss 6.1epss 0.36

    Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not being escaped. An attacker could trick a user with access to the user interface of a Revive Adserver…

  • CVE-2013-5954Apr 25, 2014
    risk 0.03cvss epss 0.03

    Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertisers via admin/advertiser-delete.php, (3)…

  • CVE-2021-22888MedMar 25, 2021
    risk 0.02cvss 6.1epss 0.20

    Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and…

  • CVE-2021-22875MedJan 28, 2021
    risk 0.02cvss 6.1epss 0.18

    Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.

  • CVE-2021-22874MedJan 28, 2021
    risk 0.02cvss 6.1epss 0.18

    Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.

  • CVE-2026-50743MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these…

  • CVE-2026-50745MedJun 26, 2026
    risk 0.00cvss 6.1epss 0.00

    A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing…

  • CVE-2026-50744MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session was not invalidated. As…

  • CVE-2026-50742MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is…

  • CVE-2026-50741HigJun 26, 2026
    risk 0.00cvss 8.8epss 0.04

    Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method.

  • CVE-2026-50740MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.

  • CVE-2026-50739MedJun 26, 2026
    risk 0.00cvss 4.3epss 0.00

    A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7 and earlier. As a result, a low‑privileged user…

  • CVE-2026-44959HigJun 23, 2026
    risk 0.00cvss 8.8epss 0.00

    A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed…

  • CVE-2026-44958MedJun 23, 2026
    risk 0.00cvss 5.4epss 0.00

    An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten solely based on banner edit…

  • CVE-2026-44957MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, leading to inconsistent ownership relationships. This issue was exploitable only…

  • CVE-2026-34916HigJun 23, 2026
    risk 0.00cvss 8.8epss 0.01

    A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during…

  • CVE-2026-34915MedJun 23, 2026
    risk 0.00cvss 6.1epss 0.00

    A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all…

  • CVE-2026-34914HigJun 23, 2026
    risk 0.00cvss 8.3epss 0.00

    A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters…

  • CVE-2026-34913MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in…

  • CVE-2026-34912MedJun 23, 2026
    risk 0.00cvss 4.3epss 0.00

    A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same…

  • CVE-2021-22872MedJan 26, 2021
    risk 0.00cvss 6.1epss 0.03

    Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly accessible afr.php delivery script. While this issue was previously addressed in modern browsers as CVE-2020-8115, some older browsers (e.g., IE10) that do not…

  • CVE-2021-22871MedJan 26, 2021
    risk 0.00cvss 4.8epss 0.02

    Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL website property, which is then displayed unsanitized in the affiliate-preview.php tag generation screen, leading to a persistent cross-site scripting (XSS)…

  • CVE-2015-7373Oct 14, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the "magic-macros" feature in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via a GET parameter, which is not properly handled in a banner.

  • CVE-2015-7372Oct 14, 2015
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the layerstyle parameter.

  • CVE-2015-7371Oct 14, 2015
    risk 0.00cvss epss 0.03

    Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possibly cause a denial of service (resource consumption) via a direct request.

  • CVE-2015-7370Oct 14, 2015
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in open-flash-chart.swf in Open Flash Chart 2, as used in the VideoAds plugin in Revive Adserver before 3.2.2 and CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2…

  • CVE-2015-7369Oct 14, 2015
    risk 0.00cvss epss 0.03

    The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.

  • CVE-2015-7368Oct 14, 2015
    risk 0.00cvss epss 0.01

    Revive Adserver before 3.2.2 does not send the appropriate Cache-Control HTTP headers in responses for admin UI pages, which allows local users to obtain sensitive information via the web browser cache.

  • CVE-2015-7367Oct 14, 2015
    risk 0.00cvss epss 0.03

    Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked.

  • CVE-2015-7366Oct 14, 2015
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authentication of users for requests that (1) perform certain plugin actions and possibly cause a denial of service (disabled core plugins) via unknown…

  • CVE-2015-7365Oct 14, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the plugin upgrade form in Revive Adserver before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of an uploaded file containing errors.

  • CVE-2015-7364Oct 14, 2015
    risk 0.00cvss epss 0.01

    The HTML_Quickform library, as used in Revive Adserver before 3.2.2, allows remote attackers to bypass the CSRF protection mechanism via an empty token.

  • CVE-2014-9407Dec 19, 2014
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) delete data via a request to agency-delete.php, (2) tracker-delete.php, or (3)…

  • CVE-2014-8875Dec 19, 2014
    risk 0.00cvss epss 0.03

    The XML_RPC_cd function in lib/pear/XML/RPC.php in Revive Adserver before 3.0.6 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted XML-RPC request, aka an XML Entity Expansion (XEE) attack.

  • CVE-2014-8793Dec 19, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in lib/max/Admin/UI/Field/PublisherIdField.php in Revive Adserver before 3.0.6 allows remote attackers to inject arbitrary web script or HTML via the refresh_page parameter to www/admin/report-generate.php.

  • CVE-2013-7149Dec 28, 2013
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.

Page 2 of 2