📦 Clipbucket

by Oxygenz

🔍 What is Clipbucket?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21875

CRITICAL CVSS 9.8 Jan 8, 2026

ClipBucket v5 versions 5.5.2-#187 and below contain a blind SQL injection vulnerability in the comment functionality. Attackers can exploit this by injecting malicious SQL payloads through the obj_id ...

CVE-2025-67418

CRITICAL CVSS 9.8 Dec 22, 2025

ClipBucket 5.5.2 ships with hardcoded default administrative credentials, allowing unauthenticated remote attackers to gain full administrative control of the application. This affects all deployments...

CVE-2025-64338

CRITICAL CVSS 9.0 Nov 7, 2025

ClipBucket v5 versions 5.5.2-#156 and below contain a stored cross-site scripting (XSS) vulnerability in the photo collection name field. Authenticated regular users can inject malicious scripts that ...

CVE-2025-21624

CRITICAL CVSS 9.8 Jan 7, 2025

ClipBucket V5 has a file upload vulnerability in the Manage Playlist functionality that allows attackers to upload PHP script files disguised as playlist cover images. This can lead to webshell deploy...

CVE-2024-54135

CRITICAL CVSS 9.8 Dec 6, 2024

This CVE describes a PHP deserialization vulnerability in ClipBucket V5 video hosting software that allows attackers to execute arbitrary code by sending malicious serialized objects. The vulnerabilit...

CVE-2026-25728

HIGH CVSS 7.5 Feb 10, 2026

ClipBucket v5 versions before 5.5.3 - #40 have a TOCTOU race condition in avatar/background image uploads. Attackers can upload malicious PHP files that execute arbitrary code before validation delete...

CVE-2025-62429

HIGH CVSS 7.2 Oct 20, 2025

This vulnerability allows remote code execution in ClipBucket v5 video sharing platform. Attackers can inject malicious PHP code through the 'type' parameter in update_launch.php, enabling them to exe...

CVE-2025-21623

HIGH CVSS 7.5 Jan 7, 2025

This vulnerability in ClipBucket V5 allows unauthenticated attackers to perform directory traversal attacks to change the template directory, leading to denial of service. All ClipBucket V5 installati...

CVE-2025-21622

HIGH CVSS 7.5 Jan 7, 2025

This CVE describes a path traversal vulnerability in ClipBucket V5's avatar upload feature. Attackers can delete arbitrary files on the server by manipulating avatar URLs with directory traversal sequ...

CVE-2026-26005

MEDIUM CVSS 5.0 Feb 12, 2026

ClipBucket v5's Remote Play feature allows users to create video entries referencing external URLs. Attackers can exploit this by specifying internal network hosts in video URLs, triggering Server-Sid...

CVE-2025-65113

MEDIUM CVSS 6.5 Nov 29, 2025

ClipBucket v5 has an authorization bypass vulnerability in its AJAX flagging system that allows unauthenticated users to flag any content (users, videos, photos, collections). This affects all ClipBuc...

CVE-2025-62709

MEDIUM CVSS 6.8 Nov 20, 2025

ClipBucket v5.5.2 has a host header injection vulnerability that allows attackers to manipulate password reset links. When the base_url configuration isn't set, the application uses the client-control...

CVE-2025-64339

MEDIUM CVSS 5.4 Nov 7, 2025

ClipBucket v5 has a stored XSS vulnerability in the Manage Playlists feature where authenticated low-privileged users can inject malicious JavaScript into playlist names. This code executes in the bro...

CVE-2025-64336

MEDIUM CVSS 5.4 Nov 7, 2025

ClipBucket v5 versions 5.5.2-#146 and below contain a stored XSS vulnerability in the Manage Photos feature. Authenticated regular users can inject malicious JavaScript into photo titles that executes...

CVE-2025-62715

MEDIUM CVSS 5.4 Nov 4, 2025

ClipBucket v5 versions 5.5.2-#147 and below contain a stored XSS vulnerability in the Collection tags feature. Authenticated normal users can inject malicious JavaScript into tags, which executes in t...

CVE-2025-62430

MEDIUM CVSS 5.4 Oct 17, 2025

ClipBucket v5 through build 5.5.2 #145 has stored cross-site scripting (XSS) vulnerabilities in video and photo metadata fields. Authenticated users can inject malicious scripts that execute when any ...

CVE-2025-62423

MEDIUM CVSS 6.7 Oct 16, 2025

This is a blind SQL injection vulnerability in ClipBucket V5's admin login-as-user functionality. Attackers with admin access can exploit it to extract database information or potentially gain unautho...

CVE-2025-55911

MEDIUM CVSS 6.5 Sep 18, 2025

This vulnerability in ClipBucket v5.5.2 Build#90 allows remote attackers to execute arbitrary code via the file_downloader.php component by manipulating the file parameter. It affects all systems runn...