CVE-2025-55126: XSS
Published Nov 20, 2025
·Updated
HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box at the top of advertiser-related pages, with campaign names being the vector for the stored XSS
Affected Software
1 affected component
Aquaplatform Revive Adserver>=6.0.0<6.0.3
Event History
Nov 20, 2025
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
DescriptionSeverity
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55126?
CVE-2025-55126 has been classified as a medium severity stored XSS vulnerability.
2
How do I fix CVE-2025-55126?
To mitigate CVE-2025-55126, update Aquaplatform Revive Adserver to version 6.0.4 or later.
3
What versions of Aquaplatform Revive Adserver are affected by CVE-2025-55126?
CVE-2025-55126 affects Aquaplatform Revive Adserver versions between 6.0.0 and 6.0.3.
4
What type of vulnerability is CVE-2025-55126?
CVE-2025-55126 is a stored cross-site scripting (XSS) vulnerability.
5
Who reported the CVE-2025-55126 vulnerability?
CVE-2025-55126 was reported by Dang Hung Vi, a member of the HackerOne community.