Back to Database
Status published
Low
CVE-2025-55123
Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1...
Vulnerability Description
Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-55123
Credits & Attribution
No credits recorded in the NVD database.
References
More from Revive
View All →CVE-2025-55129
HackerOne community member Kassem S.(kassem_s94) has reported that username handling...
Medium
5.4
CVE-2025-55128
HackerOne community member Dang Hung Vi (vidang04) has reported an...
Medium
6.5
CVE-2025-55127
HackerOne community member Dao Hoang Anh (yoyomiski) has reported an...
Unknown
0
CVE-2025-55126
HackerOne community member Dang Hung Vi (vidang04) has reported a...
Medium
6.5
CVE-2025-55124
Improper neutralisation of input in Revive Adserver 6.0.0+ causes a...
Medium
6.1
Affected Vendor
Revive
View all reports →Affected Software
Revive Adserver
Vulnerable Versions:
6, 5, 6.0.2, 5.5.3
Timeline
Official Publish:
November 20th, 2025
Last Modified:
November 20th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.