CVE-2025-52668: XSS
Published Nov 20, 2025
·Updated
Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.
Affected Software
3 affected components
Revive Adserver<=6.0.1
revive-adserver Revive Adserver<=5.5.2
revive-adserver Revive Adserver>=6.0.0<=6.0.1
Event History
Nov 20, 2025
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionSeverity
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52668?
CVE-2025-52668 has been classified as a critical vulnerability due to its potential for information disclosure and session hijacking.
2
What versions of Revive Adserver are affected by CVE-2025-52668?
CVE-2025-52668 affects Revive Adserver versions 5.5.2 and 6.0.1 and earlier.
3
How do I fix CVE-2025-52668?
To fix CVE-2025-52668, upgrade to a patched version of Revive Adserver beyond 6.0.1.
4
What type of attack is associated with CVE-2025-52668?
CVE-2025-52668 is associated with a stored XSS attack that can lead to information disclosure.
5
Is CVE-2025-52668 something that can lead to session hijacking?
Yes, CVE-2025-52668 can potentially lead to session hijacking due to improper input neutralization.