CVE-2025-55128: Aquaplatform Revive Adserver
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of items per page, potentially leading to a denial of service.
Affected products
- Aquaplatform Revive Adserver: from 6.0.0, before 6.0.3 (fixed in 6.0.3)
Published 2025-11-20. Last modified 2026-09-26.