CVE-2026-50745

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing user‑supplied input to be reflected without escaping.
References
Link Resource
https://hackerone.com/reports/3793243 Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*

History

29 Jun 2026, 20:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.7
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*
First Time Revive-adserver revive Adserver
Revive-adserver
References () https://hackerone.com/reports/3793243 - () https://hackerone.com/reports/3793243 - Issue Tracking

26 Jun 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 02:16

Updated : 2026-06-29 20:17


NVD link : CVE-2026-50745

Mitre link : CVE-2026-50745

CVE.ORG link : CVE-2026-50745


JSON object : View

Products Affected

revive-adserver

  • revive_adserver
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')