{"id":"CVE-2025-27208","title":"A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2","summary":"A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically cra…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79","CWE-79"],"vendor":"revive-adserver","product":"revive_adserver","affected":["revive_adserver < 6.0.0","revive_adserver = 6.0.0"],"patched":["revive_adserver 6.0.0"],"published":"2025-10-31","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-27208","references":[{"url":"https://hackerone.com/reports/3091390","label":"support@hackerone.com"},{"url":"http://seclists.org/fulldisclosure/2025/Oct/20","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01469,"epssPercentile":0.72933,"ingestedAt":"2026-10-07T21:54:14.908Z","slug":"CVE-2025-27208","body":"## Overview\n\nA reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser.  The session cookie cannot be accessed, but a number of other operations could be performed.\r\n\r\nThe vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.\n\n## Affected\n\n- `revive_adserver < 6.0.0`\n- `revive_adserver = 6.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `revive_adserver 6.0.0`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}