CVE Tools

Revive

30 CVEs tracked since 2025. Since Nov 2025, none of them reached CISA KEV.

Revive CVEs per month

Nov 2025 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Revive CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-11130
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06170

Products

The products that kept showing up in Revive's monthly top three, with their CVEs summed over those months.

  1. Adserver171 month
  2. Revive Adserver131 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Revive.

  1. CVE-2026-50743A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests withou...5.4
  2. CVE-2026-50739A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` scri...4.3
  3. CVE-2026-50744A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the m...4.3
  4. CVE-2026-50742A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed witho...5.4
  5. CVE-2026-50740A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFr...5.4
  6. CVE-2026-50745A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty c...6.1
  7. CVE-2026-50741Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin ide...8.8
  8. CVE-2026-44958An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php ...5.4
  9. CVE-2026-44961The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks...—
  10. CVE-2026-44957A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities...4.3
  11. CVE-2026-44956Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog ...—
  12. CVE-2026-44960A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log details for affected entries, any malicious JavaScript payload embedded in the...—
  13. CVE-2026-44959A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malic...8.8
  14. CVE-2026-34913A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their tra...4.3
  15. CVE-2026-34912A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user co...4.3

The record

Peak rank
#59 in Jun 2026
Busiest month shown
Jun 2026, 17 CVEs
Months with a KEV entry
0 since Nov 2025
Monthly snapshots
2 since 2025
Revive's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store