Unrated severityNVD Advisory· Published Feb 27, 2026· Updated Feb 27, 2026
ClipBucket v5 has Stored XSS via Collection name
CVE-2026-26997
Description
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can store the XSS payload. The payload is triggered by administrator. Version 5.5.3 #59 fixes the issue.
Affected products
1- Range: < 5.5.3 #59
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/MacWarrior/clipbucket-v5/commit/2da4c8e41f9e4baf47ff89f8a674fbe9b63ac76dmitrex_refsource_MISC
- github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-97r6-4hmx-hcrhmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.