« Back to list

Aquaplatform

Aquaplatform Revive Adserver: vulnerabilities and CVEs

Aquaplatform Revive Adserver has 9 published vulnerabilities, 9 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months9
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-21664Medium (6.1)0.20%—Jan 20, 2026
HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that includes an HTML…
CVE-2026-21663Medium (6.1)0.20%—Jan 20, 2026
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML payload in a…
CVE-2026-21642Medium (6.1)0.20%—Jan 20, 2026
HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL that includes an…
CVE-2026-21641Medium (6.5)0.27%—Jan 20, 2026
HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are mistakenly allowed…
CVE-2026-21640Low (2.7)0.25%—Jan 20, 2026
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user console could be…
CVE-2025-55129Medium (5.4)0.24%—Dec 2, 2025
HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alternate techniques.…
CVE-2025-55127Medium (5.4)0.23%—Nov 20, 2025
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could be virtually…
CVE-2025-55126Medium (6.5)0.21%—Nov 20, 2025
HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for the stored XSS
CVE-2025-55128Medium (6.5)0.40%—Nov 20, 2025
HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily…