Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. HackerOne/
  3. HackerOne Response

HackerOne Response

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 17 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Vulnerability disclosure program platform for external security reporting

by HackerOne · hackerone.com · source ↗

Known CVEs (17)1 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-11325 ↗HIGH 8.8new2026

    Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain…

  • CVE-2026-21664 ↗MEDIUM 6.12026

    HackerOne community member Huynh Pham Thanh Luc (nigh7c0r3) has reported a reflected XSS vulnerability in the afr.php delivery script of Revive Adserver. An attacker can craft a specific URL that incl…

  • CVE-2026-21663 ↗MEDIUM 6.12026

    HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the banner-acl.php script of Revive Adserver. An attacker can craft a specific URL that includes an HTML pay…

  • CVE-2026-21642 ↗MEDIUM 6.12026

    HackerOne community member Patrick Lang (7yr) has reported a reflected XSS vulnerability in the `banner-acl.php` and `channel-acl.php` scripts of Revive Adserver. An attacker can craft a specific URL …

  • CVE-2026-21641 ↗MEDIUM 6.52026

    HackerOne community member Jad Ghamloush (0xjad) has reported an authorization bypass vulnerability in the `tracker-delete.php` script of Revive Adserver. Users with permissions to delete trackers are…

  • CVE-2026-21640 ↗LOW 2.72026

    HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver settings. When specific character combinations are used in a setting, the admin user …

  • CVE-2025-55129 ↗MEDIUM 5.42025

    HackerOne community member Kassem S.(kassem_s94) has reported that username handling in Revive Adserver was still vulnerable to impersonation attacks after the fix for CVE-2025-52672, via several alte…

  • CVE-2025-55128 ↗MEDIUM 6.52025

    HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could requ…

  • CVE-2025-55127 ↗MEDIUM 5.42025

    HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or trailing whitespace could b…

  • CVE-2025-55126 ↗MEDIUM 6.52025

    HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for…

  • CVE-2025-42706 ↗MEDIUM 6.52025

    A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for…

  • CVE-2025-42701 ↗MEDIUM 5.62025

    A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix …

  • CVE-2025-8573 ↗MEDIUM 4.82025

    Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page.  Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS…

  • CVE-2022-21829 ↗CRITICAL 9.82022

    Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ in…

  • CVE-2021-22970 ↗HIGH 7.52021

    Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files …

  • CVE-2020-8143 ↗MEDIUM 6.12020

    An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted …

  • CVE-2020-8142 ↗MEDIUM 6.82020

    A security restriction bypass vulnerability has been discovered in Revive Adserver version < 5.0.5 by HackerOne user hoangn144. Revive Adserver, like many other applications, requires the logged in us…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Bug Bounty products

see all →
  • Bugcrowd Platform · Bugcrowd
  • Bugcrowd Vulnerability Disclosure Program (VDP) · Bugcrowd
  • Com Olho Bug Bounty Program · Com Olho
  • Comolho Crowdsourced Security · Com Olho
  • Dreamlab CyScope · Dreamlab Technologies
  • Inspectiv Bug Bounty Program · Inspectiv
  • Inspectiv Platform · Inspectiv
  • Inspectiv VDP · Inspectiv