Vendor
Revive-Adserver vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in Revive-Adserver: 0 in the last 7 days and 1 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-50743, was published on 20 July 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 0
- Exploited in the wild
- 0
About Revive-Adserver
An open-source ad serving system that enables publishers to manage and deliver online advertising.
Revive-Adserver technologies
Latest Revive-Adserver vulnerabilities
- CVE-2026-50743: Revive Adserver CSRF in zone-include.phpmediumCVSS 5.4
- CVE-2026-50745: Revive Adserver reflected XSS in stats-video.phpmediumCVSS 4.7
- CVE-2026-50744: Revive Adserver auth bypass in XML-RPC APImediumCVSS 4.3
- CVE-2026-50742: Revive Adserver stored XSS in maintenance toolsmediumCVSS 4.4
- CVE-2026-50741: Revive Adserver code injection bypass in XML-RPC APIhighCVSS 8.8
- CVE-2026-50740: Revive Adserver reflected XSS in zone-include.phpmediumCVSS 6.1
- CVE-2026-50739: Revive Adserver improper access control in tracker-campaigns.phpmediumCVSS 4.3
- CVE-2026-44961: Revive Adserver validation bypass in XML-RPC API addUser methodinfoCVSS 0
- CVE-2026-44960: Revive Adserver stored XSS in audit log via usernamesinfoCVSS 0
- CVE-2026-44959: Revive Adserver PHP code injection in delivery limitationshighCVSS 8.8
- CVE-2026-44958: Revive Adserver access control bypass in banner-edit.phpmediumCVSS 5.4
- CVE-2026-44957: Revive Adserver improper access control in XML-RPC APImediumCVSS 4.3
- CVE-2026-44956: Revive Adserver stored XSS in userlog-details.php via Full Name fieldinfoCVSS 0
- CVE-2026-34917: Revive Adserver authentication bypass via session reuse in XML-RPC APImediumCVSS 4.3
- CVE-2026-34916: Revive Adserver PHP code injection in delivery limitationshighCVSS 8.8
- CVE-2026-34915: Revive Adserver blind SQL injection in zone-include.phpmediumCVSS 6.1
- CVE-2026-34914: Revive Adserver blind SQL injection in zone-include.phphighCVSS 8.3
- CVE-2026-34913: Revive Adserver improper access control in campaign-trackers.phpmediumCVSS 4.3
- CVE-2026-34912: Revive Adserver improper access control in zone-include.phpmediumCVSS 4.3
- CVE-2025-55124: Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.mediumCVSS 6.1EPSS 0.4%
- CVE-2025-55123: Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be…mediumCVSS 5.4EPSS 0.4%
- CVE-2025-52671: Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes…mediumCVSS 4.3EPSS 0.4%
Most severe Revive-Adserver vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-50741: Revive Adserver code injection bypass in XML-RPC APIhighCVSS 8.8
- CVE-2026-44959: Revive Adserver PHP code injection in delivery limitationshighCVSS 8.8
- CVE-2026-34916: Revive Adserver PHP code injection in delivery limitationshighCVSS 8.8
- CVE-2026-34914: Revive Adserver blind SQL injection in zone-include.phphighCVSS 8.3
- CVE-2025-55124: Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.mediumCVSS 6.1EPSS 0.4%
- CVE-2026-50740: Revive Adserver reflected XSS in zone-include.phpmediumCVSS 6.1
- CVE-2026-34915: Revive Adserver blind SQL injection in zone-include.phpmediumCVSS 6.1
- CVE-2025-55123: Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be…mediumCVSS 5.4EPSS 0.4%
- CVE-2026-50743: Revive Adserver CSRF in zone-include.phpmediumCVSS 5.4
- CVE-2026-44958: Revive Adserver access control bypass in banner-edit.phpmediumCVSS 5.4
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/revive-adserver.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Revive-Adserver vulnerabilities", https://junglewise.ai/threats/vendors/revive-adserver, 26 September 2026.