Unknown · Revive Adserver · CVE-2026-44959
**Name of the Vulnerable Software and Affected Versions**
Revive Adserver versions prior to 6.0.7
**Description**
Insufficient validation of user input occurs when saving delivery limitations. A low-privileged user can introduce an unexpected component parameter to inject malicious PHP code into the `compiledlimitations` field, which is subsequently executed during banner delivery.
**Recommendations**
Update to version 6.0.7 or later to ensure input sanitization filters out unexpected parameters.