VendorsOxygenzclipbucketany version
Vulnerabilities

Oxygenz Clipbucket any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2026-21875
ClipBucket v5 Vulnerable to Blind SQL Injection through Channel Comments
Published 2026-01-07 · Analyzed
9.8EPSS 0.018
CVE-2025-21624
ClipBucket V5 Playlist Cover File Upload to Remote Code Execution
Published 2025-01-07 · Analyzed
9.8EPSS 0.012
CVE-2024-54135
Untrusted Deserialization in ClipBucket-v5 Version 2.0 to 5.5.1 Revision 199
Published 2024-12-06 · Analyzed
9.8EPSS 0.008
CVE-2024-54136
Untrusted Deserialization in ClipBucket-v5 Version 5.5.1 Revision 199 and Below
Published 2024-12-06 · Analyzed
9.8EPSS 0.007
CVE-2025-67418
ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remote attacker can log in to the administrative panel using these default credentials, resulting in full administrative control of the application.
Published 2025-12-22 · Modified
9.8EPSS 0.005
CVE-2026-25728
ClipBucket v5 Affected by Remote Code Execution via Avatar/Background File Upload Race Condition
Published 2026-02-10 · Analyzed
9.3EPSS 0.004
CVE-2025-21622
ClipBucket V5 Avatar URL Path Traversal to Arbitrary File Delete
Published 2025-01-07 · Analyzed
9.1EPSS 0.010
CVE-2025-64338
ClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection Name
Published 2025-12-15 · Analyzed
9.0EPSS 0.005
CVE-2026-32321
ClipBucket v5 has time-based Blind SQL Injection in ajax.php that leads to Data Exfiltration
Published 2026-03-18 · Analyzed
8.8EPSS 0.005
CVE-2025-62709
ClipBucket v5 is vulnerable to password reset link manipulation
Published 2025-11-20 · Analyzed
8.8EPSS 0.004
CVE-2025-21623
ClipBucket V5 Unauthenticated Template Directory Update to Denial-of-Service
Published 2025-01-07 · Analyzed
7.5EPSS 0.011
CVE-2025-55912
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
Published 2025-09-18 · Analyzed
7.31 PoCEPSS 0.015
CVE-2025-62429
ClipBucket v5 executes arbitrary PHP code
Published 2025-10-20 · Analyzed
7.2EPSS 0.008
CVE-2025-62423
ClipBucket V5 Blind SQL injection in the Admin Panel
Published 2025-10-16 · Analyzed
7.2EPSS 0.005
CVE-2025-64336
ClipBucket v5's Manage Photo Feature is Vulnerable to Stored XSS Attack via Photo Title
Published 2025-11-07 · Analyzed
7.2EPSS 0.003
CVE-2025-64339
ClipBucket v5: Stored XSS Vulnerability in Manage Playlists
Published 2025-11-07 · Analyzed
7.2EPSS 0.003
CVE-2025-62424
ClipBucket path traversal vulnerability in template editor allows arbitrary file read and write
Published 2025-10-17 · Analyzed
6.7EPSS 0.009
CVE-2025-55911
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter
Published 2025-09-18 · Analyzed
6.51 PoCEPSS 0.011
CVE-2025-65113
ClipBucket v5 Unauthenticated Object Flagging Vulnerability
Published 2025-11-29 · Analyzed
6.5EPSS 0.004
CVE-2025-64114
ClipBucket v5: SQL Injection possible through ClipBucket Custom Fields plugin
Published 2025-11-05 · Analyzed
6.5EPSS 0.004
CVE-2026-28354
ClipBucket v5 has IDOR in Collection Item Management
Published 2026-02-27 · Analyzed
6.5EPSS 0.003
CVE-2025-62430
ClipBucket v5 stored XSS via video/photo fields
Published 2025-10-17 · Analyzed
5.4EPSS 0.003
CVE-2026-26997
ClipBucket v5 has Stored XSS via Collection name
Published 2026-02-27 · Analyzed
5.4EPSS 0.002
CVE-2025-62715
ClipBucket v5: Stored XSS via Collection Tags
Published 2025-11-04 · Analyzed
5.4EPSS 0.002
CVE-2026-26005
ClipBucket v5 enables internal network scans via an SSRF vulnerability
Published 2026-02-12 · Analyzed
5.0EPSS 0.003