🔐 CVE Alert

CVE-2026-34915

MEDIUM 6.1
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.

CWE CWE-79
Vendor revive
Product adserver
Published Jun 23, 2026
Last Updated Jun 23, 2026
Stay Ahead of the Next One

Get instant alerts for revive adserver

Be the first to know when new medium vulnerabilities affecting revive adserver are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected Versions

Revive / Adserver
0 ≤ 6.0.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
hackerone.com: https://hackerone.com/reports/3653316

Credits

🔍 Kaushalendra Dubey (titanrain)