ReviveAdserver Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2026-50740
A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A lowprivileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.