CVE-2026-50742

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the affected maintenance tools is not entirely under the attacker's control.
References
Link Resource
https://hackerone.com/reports/3781311 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*

History

29 Jun 2026, 20:20

Type Values Removed Values Added
References () https://hackerone.com/reports/3781311 - () https://hackerone.com/reports/3781311 - Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*
First Time Revive-adserver revive Adserver
Revive-adserver
CVSS v2 : unknown
v3 : 4.4
v2 : unknown
v3 : 5.4

26 Jun 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 02:16

Updated : 2026-06-29 20:20


NVD link : CVE-2026-50742

Mitre link : CVE-2026-50742

CVE.ORG link : CVE-2026-50742


JSON object : View

Products Affected

revive-adserver

  • revive_adserver
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')