VYPR

Clipbucket

by Clip Bucket

Source repositories

CVEs (49)

  • CVE-2025-62423MedOct 16, 2025
    risk 0.00cvss 6.7epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. In version5.5.2 - #140 and earlier, a Blind SQL injection vulnerability exists in the Admin Area’s “/admin_area/login_as_user.php” file. Exploiting this vulnerability requires access privileges to the Admin Area.

  • CVE-2025-21624CriJan 7, 2025
    risk 0.00cvss 9.8epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifically surrounding the uploading of playlist cover images. Without proper checks, an attacker can…

  • CVE-2025-21623HigJan 7, 2025
    risk 0.00cvss 7.5epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 238, ClipBucket V5 allows unauthenticated attackers to change the template directory via a directory traversal, which results in a denial of service.

  • CVE-2025-21622HigJan 7, 2025
    risk 0.00cvss 7.5epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. During the user avatar upload workflow, a user can choose to upload and change their avatar at any time. During deletion, ClipBucket checks for the avatar_url as a filepath within the avatars subdirectory. If the URL…

  • CVE-2024-54136CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/upload.php where the user supplied input via collection get parameter is directly…

  • CVE-2024-54135CriDec 6, 2024
    risk 0.00cvss 9.8epss 0.01

    ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are vulnerable to PHP Deserialization vulnerability. The vulnerability exists in upload/photo_upload.php within the decode_key function. User inputs were supplied…

  • CVE-2014-4187Jun 17, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in signup.php in ClipBucket allows remote attackers to inject arbitrary web script or HTML via the Username field.

  • CVE-2012-6642Apr 8, 2014
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in ClipBucket 2.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter to view_channel.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…

  • CVE-2011-3717Sep 23, 2011
    risk 0.00cvss —epss 0.01

    ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/signup_captcha/signup_captcha.php and certain other files.

Page 3 of 3