Revive Adserver is a self-hosted ad management and serving platform deployed across a range of publishers and digital media operations. Despite a narrow product footprint, the vendor maintains a moderate vulnerability presence reflecting its role as a web-facing application that handles ad delivery, user tracking, and publisher integrations. The platform's exposure spans across its core adserver product and arises from the complexity of parsing and processing untrusted input from multiple sources in the ad ecosystem. Defenders tracking this vendor should prioritize updates as part of their web-application infrastructure maintenance, since adservers often sit in the critical path between users and content delivery; current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Revive Adserver over time
Signals from CVEs in this vendor scope (67 CVEs).
67 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22873MEDIUM Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg.php and ck.php delivery scripts. Such open redirects had pr | Jan 26, 2021 | 6.1 | 68 | NO | YES |
CVE-2020-8143MEDIUM An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a s | Apr 3, 2020 | 6.1 | 59 | NO | NO |
CVE-2026-50741HIGH Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise | Jun 26, 2026 | 8.8 | 40 | NO | NO |
CVE-2021-22889MEDIUM Revive Adserver before v5.2.0 is vulnerable to a reflected XSS vulnerability in the `statsBreakdown` parameter of stats.php (and possibly other scripts) due to single quotes not be | Mar 25, 2021 | 6.1 | 37 | NO | NO |
CVE-2026-34916HIGH A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject ma | Jun 23, 2026 | 8.8 | 35 | NO | NO |
CVE-2013-5954MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delet | Apr 25, 2014 | 6.8 | 34 | NO | YES |
CVE-2020-8115MEDIUM A reflected XSS vulnerability has been discovered in the publicly accessible afr.php delivery script of Revive Adserver <= 5.0.3 by Jacopo Tediosi. There are currently no known exp | Feb 4, 2020 | 6.1 | 32 | NO | YES |
CVE-2017-5830CRITICAL Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts. | Mar 3, 2017 | 9.8 | 30 | NO | NO |
CVE-2026-50745MEDIUM A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the outpu | Jun 26, 2026 | 6.1 | 29 | NO | NO |
CVE-2026-50740MEDIUM A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh param | Jun 26, 2026 | 5.4 | 29 | NO | NO |
Signals from CVEs in this vendor scope (67 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Revive Adserver.
Media articles that mention a CVE ID that affects a product developed by Revive Adserver — matched by CVE ID, not by vendor name.