Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Revive Adserver

First CVE: Dec 28, 2013Active for: 13 yearsTotal CVEs: 127

Revive Adserver is a self-hosted ad management and serving platform deployed across a range of publishers and digital media operations. Despite a narrow product footprint, the vendor maintains a moderate vulnerability presence reflecting its role as a web-facing application that handles ad delivery, user tracking, and publisher integrations. The platform's exposure spans across its core adserver product and arises from the complexity of parsing and processing untrusted input from multiple sources in the ad ecosystem. Defenders tracking this vendor should prioritize updates as part of their web-application infrastructure maintenance, since adservers often sit in the critical path between users and content delivery; current severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
67
Total CVEs
More Total CVEs than 99% of tracked vendors
6.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Revive Adserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2013
12 years ago
Most Recent CVE
Jun 26, 2026
29 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (67 CVEs).

67 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-22873MEDIUM
Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had pr
Jan 26, 20216.168NOYES
CVE-2020-8143MEDIUM
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a s
Apr 3, 20206.159NONO
CVE-2026-50741HIGH
Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise
Jun 26, 20268.840NONO
CVE-2021-22889MEDIUM
Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not be
Mar 25, 20216.137NONO
CVE-2026-34916HIGH
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject ma
Jun 23, 20268.835NONO
CVE-2013-5954MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delet
Apr 25, 20146.834NOYES
CVE-2020-8115MEDIUM
A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exp
Feb 4, 20206.132NOYES
CVE-2017-5830CRITICAL
Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.
Mar 3, 20179.830NONO
CVE-2026-50745MEDIUM
A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the outpu
Jun 26, 20266.129NONO
CVE-2026-50740MEDIUM
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh param
Jun 26, 20265.429NONO
View all 67 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products67 CVEs
70%
19%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network51 (76.1%)
Unknown15 (22.4%)
Physical1 (1.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (73.1%)
High3 (4.5%)
Unknown15 (22.4%)
User Interaction
None17 (25.4%)
Unknown15 (22.4%)
Required35 (52.2%)
Privileges Required
Low22 (32.8%)
High4 (6.0%)
None26 (38.8%)
Unknown15 (22.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (67 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.5% of CVEs· 95th percentile
ExploitDB
1 CVE
1.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Revive Adserver.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Revive Adserver — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Revive Adserver's Products

View all 3 CNAs →

Top CWEs