Skip to content
Noroxi

Revive-adserver records

66 published records for vendor revive-adserver.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

66 records
  • An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.

    MediumCVSS 6.1No exploitEPSS 70%

    revive-adserver · revive adserverApr 3, 2020

  • Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php deli

    MediumCVSS 6.1Proof of conceptEPSS 70%

    revive-adserver · revive adserverJan 26, 2021

  • Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery sc

    CriticalCVSS 9.8No exploitEPSS 3%

    revive-adserver · revive adserverMar 3, 2017

  • Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by

    CriticalCVSS 9.8No exploitEPSS 3%

    revive-adserver · revive adserverMar 27, 2017

  • Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts.

    CriticalCVSS 9.8No exploitEPSS 2%

    revive-adserver · revive adserverMar 27, 2017

  • CVE-2016-9470
    37Monitor

    Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download.

    CriticalCVSS 9.0No exploitEPSS 2%

    revive-adserver · revive adserverMar 27, 2017

  • Bypass to the fix for CVE-2026-34916.

    HighCVSS 8.8No exploitEPSS 5%

    revive-adserver · revive adserverJun 25, 2026

  • SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logg

    HighCVSS 8.8No exploitEPSS 1%

    revive-adserver · revive adserverOct 30, 2025

  • CVE-2016-9455
    35Monitor

    Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF).

    HighCVSS 8.8No exploitEPSS 1%

    revive-adserver · revive adserverMar 27, 2017

  • CVE-2016-9127
    35Monitor

    Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF).

    HighCVSS 8.8No exploitEPSS 1%

    revive-adserver · revive adserverMar 27, 2017

  • Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email addre

    HighCVSS 8.8No exploitEPSS 1%

    revive-adserver · revive adserverNov 20, 2025

  • CVE-2016-9456
    35Monitor

    Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF).

    HighCVSS 8.8No exploitEPSS 1%

    revive-adserver · revive adserverMar 27, 2017

  • Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly ot

    MediumCVSS 6.1No exploitEPSS 31%

    revive-adserver · revive adserverMar 25, 2021

  • CVE-2019-5440
    32Monitor

    Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potential authentication b

    HighCVSS 8.1No exploitEPSS 2%

    revive-adserver · revive adserverMay 28, 2019

  • CVE-2015-7369
    31Monitor

    The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which

    HighCVSS 7.5No exploitEPSS 3%

    revive-adserver · revive adserverOct 14, 2015

  • CVE-2015-7372
    31Monitor

    Directory traversal vulnerability in delivery-dev/al.php in Revive Adserver before 3.2.2 allows remote attackers to include and execute arbi

    HighCVSS 7.5No exploitEPSS 3%

    revive-adserver · revive adserverOct 14, 2015

  • CVE-2015-7367
    31Monitor

    Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has be

    HighCVSS 7.5No exploitEPSS 3%

    revive-adserver · revive adserverOct 14, 2015

  • CVE-2013-7149
    31Monitor

    SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and Op

    HighCVSS 7.5No exploitEPSS 2%

    openx · openxDec 28, 2013

  • Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in userlog-index.php via the `period_preset` parameter.

    MediumCVSS 6.1No exploitEPSS 18%

    revive-adserver · revive adserverJan 28, 2021

  • Revive Adserver before 5.1.1 is vulnerable to a reflected XSS vulnerability in stats.php via the `setPerPage` parameter.

    MediumCVSS 6.1No exploitEPSS 18%

    revive-adserver · revive adserverJan 28, 2021

  • Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `status` parameter of campaign-zone-zones.php.

    MediumCVSS 6.1No exploitEPSS 16%

    revive-adserver · revive adserverMar 25, 2021

  • Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqid() PHP function.

    HighCVSS 7.1No exploitEPSS 3%

    revive-adserver · revive adserverSep 23, 2021

  • CVE-2013-5954
    28Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication o

    MediumCVSS 6.8Proof of conceptEPSS 3%

    openx · openxApr 25, 2014

  • CVE-2015-7364
    27Monitor

    The HTML_Quickform library, as used in Revive Adserver before 3.2.2, allows remote attackers to bypass the CSRF protection mechanism via an

    MediumCVSS 6.8No exploitEPSS 1%

    revive-adserver · revive adserverOct 14, 2015

  • CVE-2015-7366
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.2.2 allow remote attackers to hijack the authenticati

    MediumCVSS 6.8No exploitEPSS 1%

    revive-adserver · revive adserverOct 14, 2015