📦 Revive Adserver

by Aquaplatform

🔍 What is Revive Adserver?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21664

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting (XSS) vulnerability in Revive Adserver's afr.php script allows attackers to craft malicious URLs containing HTML payloads. When a logged-in administrator visits such a...

CVE-2026-21641

MEDIUM CVSS 6.5 Jan 20, 2026

This authorization bypass vulnerability in Revive Adserver allows users with tracker deletion permissions to delete trackers belonging to other accounts. It affects Revive Adserver installations where...

CVE-2026-21642

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting (XSS) vulnerability in Revive Adserver allows attackers to craft malicious URLs that execute arbitrary JavaScript in administrators' browsers when visited. This affect...

CVE-2026-21663

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting (XSS) vulnerability in Revive Adserver's banner-acl.php script allows attackers to craft malicious URLs containing HTML payloads. When a logged-in administrator visits...

CVE-2025-55129

MEDIUM CVSS 5.4 Dec 2, 2025

This vulnerability allows attackers to impersonate legitimate users in Revive Adserver through homoglyph and alternative character techniques, bypassing previous security fixes. It affects systems run...

CVE-2025-55127

MEDIUM CVSS 5.4 Nov 20, 2025

This vulnerability allows attackers to create usernames with leading or trailing whitespace that appear identical to legitimate usernames in the UI, potentially enabling impersonation attacks. It affe...

CVE-2025-55128

MEDIUM CVSS 6.5 Nov 20, 2025

An uncontrolled resource consumption vulnerability in userlog-index.php allows authenticated admin users to request arbitrarily large page sizes, potentially causing denial of service through excessiv...

CVE-2025-55126

MEDIUM CVSS 6.5 Nov 20, 2025

This stored XSS vulnerability allows attackers to inject malicious scripts into advertiser campaign names, which then execute when users view affected pages. The vulnerability affects users accessing ...

CVE-2026-21640

LOW CVSS 2.7 Jan 20, 2026

A format string injection vulnerability in Revive Adserver allows attackers to cause a fatal PHP error that disables the admin console. This affects administrators of Revive Adserver installations who...