A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.
We have discovered 9,775 live websites that are affected by CVE-2026-50743.
| Product | |
| Category | Advertising Networks |
| Vulnerable Domains | 9,775 live websites (100% of Revive Adserver install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 59 versions ( 98% of all versions) |
| 2,830 websites | |
| 2,264 websites | |
| 640 websites | |
| 475 websites | |
| 373 websites | |
| 211 websites | |
| 179 websites | |
| 178 websites | |
| 172 websites | |
| 154 websites |
| .com | 3,119 websites |
| .de | 1,548 websites |
| .net | 592 websites |
| .pl | 358 websites |
| .org | 286 websites |
| .it | 161 websites |
| .com.br | 147 websites |
| .info | 143 websites |
| .ru | 137 websites |
| .nl | 118 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.******.jp | *,*** | ||
| *.******.net | *,*** | ||
| ***.****.******.jp | *,*** | ||
| ***********.ro | **,*** | ||
| ***********.com | **,*** | ||
| ***.de | **,*** | ||
| ***************.nl | **,*** | ||
| ********.com | **,*** | ||
| ***.se | **,*** | ||
| ****.org | **,*** |
FAQ