CVE-2026-50745

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing user‑supplied input to be reflected without escaping.
References
Link Resource
https://hackerone.com/reports/3793243 Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:revive-adserver:revive_adserver:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-26 02:16

Updated : 2026-06-29 20:17


NVD link : CVE-2026-50745

Mitre link : CVE-2026-50745

CVE.ORG link : CVE-2026-50745


JSON object : View

Products Affected

revive-adserver

  • revive_adserver
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')