csanz
8 exploits
Active since Oct 2025
ClipBucket v5 has time-based Blind SQL Injection in ajax.php that leads to Data Exfiltration
CVSS 8.8
ClipBucket 5.3-5.5.3-59 - Authenticated Stored Cross-Site Scripting
CVSS 5.4
ClipBucket 5.3-5.5.2-140 - Authenticated Blind SQL Injection in Admin Login as User
CVSS 6.7
ClipBucket 5.3-5.5.2-146 - Authenticated Path Traversal and Arbitrary File Write via Template Editor Folder Parameter
CVSS 6.7
ClipBucket 5.3-5.5.2-163 - Password Reset Token Hijacking via Host Header Injection
CVSS 6.8
ClipBucket 5.3-5.5.2-151 - Authenticated SQL Injection via Custom Fields Plugin
CVSS 6.5
ClipBucket 5.3-5.5.2-164 - Unauthenticated Authorization Bypass via AJAX Flagging System
CVSS 6.5
ClipBucket 5.3-5.5.3-40 - Remote Code Execution via Avatar and Background Image Upload Race Condition
CVSS 7.5