VulnSea

revive_adserver vulnerabilities

CVEs whose affected-version data names the revive_adserver package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2025-55124Medium· 6.1
10mo ago

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.41%via NVD
CVE-2025-55123Medium· 5.4
10mo ago

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.45%via NVD
CVE-2025-52671Medium· 4.3
10mo ago

Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.

Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to acquire information about the software, PHP and database versions currently in use.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.35%via NVD
CVE-2025-52670Medium· 6.5
10mo ago

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.32%via NVD
CVE-2025-52669Medium· 4.3
10mo ago

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes non-admin users to have access to the contact name and email address of other users on the system.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.29%via NVD
CVE-2025-52668Medium· 5.4
10mo ago

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.53%via NVD
CVE-2025-52667Medium· 5.4
10mo ago

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.37%via NVD
CVE-2025-52666Low· 2.7
10mo ago

Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.

Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an administrator user to disable the admin user console due to a fatal PHP error.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.42%via NVD
CVE-2025-55128Medium· 6.5
10mo ago

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of it…

▾ Sunlitaquaplatform · revive_adserverEPSS 0.40%via NVD
CVE-2025-48987Medium· 6.1
10mo ago

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.51%via NVD
CVE-2025-48986High· 8.8
10mo ago

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

▾ Twilightrevive-adserver · revive_adserverEPSS 0.62%via NVD
revive_adserver vulnerabilities (CVEs) · VulnSea