aquaplatform records
9 published records for vendor aquaplatform.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-134 Use of Externally-Controlled Format String1
- CWE-156 Improper Neutralization of Whitespace1
- CWE-176 Improper Handling of Unicode Encoding1
- CWE-285 Improper Authorization1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2025-55128No exploit | HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.phpaquaplatform · revive adserver · CWE-400 | Medium6.5 | — | 0.4% | Nov 20, 2025 |
26Monitor | CVE-2026-21641No exploit | HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Reaquaplatform · revive adserver · CWE-285 | Medium6.5 | — | 0.3% | Jan 20, 2026 |
26Monitor | CVE-2025-55126No exploit | HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertaquaplatform · revive adserver · CWE-79 | Medium6.5 | — | 0.2% | Nov 20, 2025 |
24Monitor | CVE-2026-21664No exploit | HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revaquaplatform · revive adserver · CWE-79 | Medium6.1 | — | 0.2% | Jan 20, 2026 |
24Monitor | CVE-2026-21642No exploit | HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripaquaplatform · revive adserver · CWE-79 | Medium6.1 | — | 0.2% | Jan 20, 2026 |
24Monitor | CVE-2026-21663No exploit | HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver.aquaplatform · revive adserver · CWE-79 | Medium6.1 | — | 0.2% | Jan 20, 2026 |
21Monitor | CVE-2025-55129No exploit | HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonatioaquaplatform · revive adserver · CWE-176 | Medium5.4 | — | 0.2% | Dec 1, 2025 |
21Monitor | CVE-2025-55127No exploit | HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new uaquaplatform · revive adserver · CWE-156 | Medium5.4 | — | 0.2% | Nov 20, 2025 |
10Monitor | CVE-2026-21640No exploit | HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings.aquaplatform · revive adserver · CWE-134 | Low2.7 | — | 0.2% | Jan 20, 2026 |
- CVE-2025-5512826Monitor
HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php
MediumCVSS 6.5No exploitEPSS 0%aquaplatform · revive adserverNov 20, 2025
- CVE-2026-2164126Monitor
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Re
MediumCVSS 6.5No exploitEPSS 0%aquaplatform · revive adserverJan 20, 2026
- CVE-2025-5512626Monitor
HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advert
MediumCVSS 6.5No exploitEPSS 0%aquaplatform · revive adserverNov 20, 2025
- CVE-2026-2166424Monitor
HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Rev
MediumCVSS 6.1No exploitEPSS 0%aquaplatform · revive adserverJan 20, 2026
- CVE-2026-2164224Monitor
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scrip
MediumCVSS 6.1No exploitEPSS 0%aquaplatform · revive adserverJan 20, 2026
- CVE-2026-2166324Monitor
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver.
MediumCVSS 6.1No exploitEPSS 0%aquaplatform · revive adserverJan 20, 2026
- CVE-2025-5512921Monitor
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonatio
MediumCVSS 5.4No exploitEPSS 0%aquaplatform · revive adserverDec 1, 2025
- CVE-2025-5512721Monitor
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new u
MediumCVSS 5.4No exploitEPSS 0%aquaplatform · revive adserverNov 20, 2025
- CVE-2026-2164010Monitor
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings.
LowCVSS 2.7No exploitEPSS 0%aquaplatform · revive adserverJan 20, 2026