Stored XSS Vulnerability in Revive Adserver by Revive Adserver
CVE-2025-52668

8.7HIGH

Key Information:

Vendor

Revive

Vendor
CVE Published:
20 November 2025

What is CVE-2025-52668?

In Revive Adserver, an improper input neutralization issue exists in the stats-conversions.php script. This vulnerability allows attackers to carry out stored cross-site scripting (XSS) attacks, potentially leading to information disclosure or session hijacking. Attackers can exploit this flaw to inject malicious scripts that execute under the user's context, compromising security and privacy.

Affected Version(s)

Revive Adserver 6 <= 6.0.1

Revive Adserver 5 <= 5.5.2

Revive Adserver 6.0.2

References

CVSS V3.0

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52668 : Stored XSS Vulnerability in Revive Adserver by Revive Adserver