Loading
Generated remediation guidance and an executive summary. No account required.
Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user with enough privileges to create other users could exploit the vulnerability to access the administrator account.
Use CWE-79, Revive-Adserver vendor hub and Revive Adserver product page to widen CVE-2016-9126 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-48986, CVE-2025-52664 and CVE-2025-52670 for nearby disclosures in the same product family.