Filtered by vendor Revive Subscriptions
Total 5 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-27208 1 Revive 1 Adserver 2025-11-04 N/A
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker could trick a user with access to the user interface of a Revive Adserver instance into clicking on a specifically crafted URL and execute injected JavaScript code in the context of the victim's browser. The session cookie cannot be accessed, but a number of other operations could be performed. The vulnerability is present in the admin-search.php file and can be exploited via the compact parameter.
CVE-2025-52664 1 Revive 1 Adserver 2025-11-04 N/A
SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users
CVE-2025-62954 2 Revive, Wordpress 2 Revive Old Posts, Wordpress 2025-10-28 8.8 High
Missing Authorization vulnerability in Codeinwp Revive Old Posts tweet-old-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Revive Old Posts: from n/a through <= 9.3.3.
CVE-2022-4680 1 Revive 1 Revive Old Posts 2025-03-27 7.2 High
The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
CVE-2023-26756 1 Revive 1 Adserver 2024-11-21 7.5 High
The login page of Revive Adserver v5.4.1 is vulnerable to brute force attacks. NOTE: The vendor's position is that this is effectively mitigated by rate limits and password-quality features.