Revive develops a narrowly scoped portfolio centered on its ad server and content-syndication products for web publishers. The observed vulnerability pattern centers on improper restriction of excessive authentication attempts, reflecting the login and session-management surface exposed by web-facing advertising and publishing tools. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Revive over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50741HIGH Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise | Jun 26, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-34914HIGH A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blin | Jun 23, 2026 | 8.3 | 30 | NO | NO |
CVE-2026-50745MEDIUM A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the outpu | Jun 26, 2026 | 6.1 | 29 | NO | NO |
CVE-2026-50740MEDIUM A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh param | Jun 26, 2026 | 5.4 | 29 | NO | NO |
CVE-2026-44959HIGH A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter a | Jun 23, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-50742MEDIUM A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names bein | Jun 26, 2026 | 5.4 | 28 | NO | NO |
CVE-2026-50743MEDIUM A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POS | Jul 20, 2026 | 5.4 | 26 | NO | NO |
CVE-2026-50739MEDIUM A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campai | Jun 26, 2026 | 4.3 | 25 | NO | NO |
CVE-2026-50744MEDIUM A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and a | Jun 26, 2026 | 4.3 | 25 | NO | NO |
CVE-2023-26756HIGH The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits and password-quality | Apr 14, 2023 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Revive.
Media articles that mention a CVE ID that affects a product developed by Revive — matched by CVE ID, not by vendor name.