Junglewise Threat Intelligence

CVE-2026-50745: Revive Adserver reflected XSS in stats-video.php

CVE-2026-50745 · Severity: medium · CVSS 4.7 · Published 2026-06-26

Technologies: Revive Adserver. Vendors: Revive-Adserver.

Executive brief

A security vulnerability exists in Revive Adserver, a platform used for managing and serving digital advertisements. An attacker could trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login session information or the performance of unauthorized actions on behalf of the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability (CWE-79) exists in the stats-video.php script of Revive Adserver. The vulnerability stems from the 'url' Smarty custom helper function, which fails to properly encode or sanitize output before reflecting it in the web page. An unauthenticated remote attacker can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's browser session. The attack requires some user interaction and is mitigated by the high complexity of constructing valid URLs that bypass existing best practices. The issue is present in versions up to and including 6.0.7.

Affected products

  • Revive Adserver <= 6.0.7

Timeline

  • 2026-06-26: advisory: NVD publication date

References

Related threats