MacWarrior
20 exploits
Active since Dec 2024
ClipBucket v5 has time-based Blind SQL Injection in ajax.php that leads to Data Exfiltration
CVSS 8.8
ClipBucket 5.3-5.5.3-59 - Authenticated Stored Cross-Site Scripting
CVSS 5.4
ClipBucket V5 <5.5.1 - Code Injection
CVSS 9.8
ClipBucket V5 <5.5.1.199 - Code Injection
CVSS 9.8
ClipBucket >=5.3 <5.5.1-237 - Unauthenticated Path Traversal and Arbitrary File Deletion via Avatar URL Parameter
CVSS 7.5
ClipBucket 5.3-5.5.1-238 - Unauthenticated Path Traversal and Denial of Service via Template Directory
CVSS 7.5
ClipBucket 5.3-5.5.1-239 - Unrestricted PHP File Upload via Playlist Cover Image
CVSS 9.8
ClipBucket 5.3-5.5.2-140 - Authenticated Blind SQL Injection in Admin Login as User
CVSS 6.7
ClipBucket 5.3-5.5.2-146 - Authenticated Path Traversal and Arbitrary File Write via Template Editor Folder Parameter
CVSS 6.7
ClipBucket 5.3-5.5.2-147 - Remote Code Execution via Update Launch Type Parameter
CVSS 7.2
ClipBucket 5.3-5.5.2-145 - Stored Cross-Site Scripting in Video and Photo Metadata Fields
CVSS 5.4
ClipBucket 5.3-5.5.2-163 - Password Reset Token Hijacking via Host Header Injection
CVSS 6.8
ClipBucket 5.3-5.5.2-147 - Authenticated Stored Cross-Site Scripting in Collection Tags
CVSS 5.4
ClipBucket 5.3-5.5.2-151 - Authenticated SQL Injection via Custom Fields Plugin
CVSS 6.5
ClipBucket 5.3-5.5.2-146 - Authenticated Stored Cross-Site Scripting via Photo Title
CVSS 5.4
ClipBucket 5.5.2-#156 and below - Authenticated Stored Cross-Site Scripting via Photo Collection Name
CVSS 9.0
ClipBucket 5.3-5.5.2-146 - Authenticated Stored Cross-Site Scripting via Playlist Name Field
CVSS 5.4
ClipBucket 5.3-5.5.2-164 - Unauthenticated Authorization Bypass via AJAX Flagging System
CVSS 6.5
ClipBucket 5.3-5.5.3-40 - Remote Code Execution via Avatar and Background Image Upload Race Condition
CVSS 7.5
ClipBucket 5.3-5.5.3-45 - Server-Side Request Forgery via Remote Play Video URL
CVSS 5.0