CVE-2026-103766ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 10/01/2026 Severity High CVE-2026-102570ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 09/29/2026 Severity High CVE-2026-102569ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 09/29/2026 Severity High CVE-2026-100372ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 09/25/2026 Severity High CVE-2026-96272ClipBucket v5 before 5.5.3-#182 SQL Injection via search_result.php Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 09/23/2026 Severity High CVE-2026-95812ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 09/22/2026 Severity Medium CVE-2026-77929ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint Exploitation status Not known exploited Fix YesAffected product C clipbucket-v5 Published 09/18/2026 Severity High CVE-2026-77928ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint Exploitation status Not known exploited Fix YesAffected product C clipbucket-v5 Published 09/18/2026 Severity High CVE-2026-77927ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint Exploitation status Not known exploited Fix YesAffected product C clipbucket-v5 Published 09/18/2026 Severity High CVE-2026-80138ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter Exploitation status Not known exploited Fix YesAffected product C clipbucket-v5 Published 08/25/2026 Severity Critical CVE-2026-49482ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 06/11/2026 Severity Medium CVE-2026-47238ClipBucket: IDOR in videos subtitle editor Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 06/11/2026 Severity Medium CVE-2026-45060ClipBucket: Blind SQL Injection in progress_video.php Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 06/11/2026 Severity Critical CVE-2026-42846ClipBucket: Remote Play URL Command Injection Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 06/11/2026 Severity Critical CVE-2026-45418ClipBucket: Blind SQL Injection in subtitle_edit.php Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 06/11/2026 Severity High CVE-2026-42847ClipBucket: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 05/14/2026 Severity High CVE-2026-32321ClipBucket v5 has time-based Blind SQL Injection in ajax.php that leads to Data Exfiltration Exploitation status Public exploit Fix Not confirmed Affected product C clipbucket-v5 Published 03/18/2026 Severity High CVE-2026-28354ClipBucket v5 has IDOR in Collection Item Management Exploitation status Public exploit Fix Not confirmed Affected product C clipbucket-v5 Published 02/27/2026 Severity Medium CVE-2026-26997ClipBucket v5 has Stored XSS via Collection name Exploitation status Public exploit Fix Not confirmed Affected product C clipbucket-v5 Published 02/27/2026 Severity Low CVE-2026-26005ClipBucket v5 enables internal network scans via an SSRF vulnerability Exploitation status Public exploit Fix Not confirmed Affected product C clipbucket-v5 Published 02/12/2026 Severity Medium CVE-2026-25728ClipBucket v5 Affected by Remote Code Execution via Avatar/Background File Upload Race Condition Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 02/10/2026 Severity Critical CVE-2026-21875ClipBucket v5 Vulnerable to Blind SQL Injection through Channel Comments Exploitation status Public exploit Fix Not confirmed Affected product C clipbucket-v5 Published 01/07/2026 Severity Critical CVE-2025-64338ClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection Name Exploitation status Not known exploited Fix YesAffected product C clipbucket-v5 Published 12/15/2025 Severity Medium CVE-2025-65113ClipBucket v5 Unauthenticated Object Flagging Vulnerability Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 11/29/2025 Severity Medium CVE-2025-62709ClipBucket v5 is vulnerable to password reset link manipulation Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 11/20/2025 Severity Medium CVE-2025-64339ClipBucket v5: Stored XSS Vulnerability in Manage Playlists Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 11/07/2025 Severity High CVE-2025-64336ClipBucket v5's Manage Photo Feature is Vulnerable to Stored XSS Attack via Photo Title Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 11/07/2025 Severity High CVE-2025-64114ClipBucket v5: SQL Injection possible through ClipBucket Custom Fields plugin Exploitation status Not known exploited Fix YesAffected product C clipbucket-v5 Published 11/05/2025 Severity Medium CVE-2025-62715ClipBucket v5: Stored XSS via Collection Tags Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 11/04/2025 Severity Medium CVE-2025-62429ClipBucket v5 executes arbitrary PHP code Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 10/20/2025 Severity High CVE-2025-62430ClipBucket v5 stored XSS via video/photo fields Exploitation status Public exploit Fix Not confirmed Affected product C clipbucket-v5 Published 10/17/2025 Severity Medium CVE-2025-62424ClipBucket path traversal vulnerability in template editor allows arbitrary file read and write Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 10/17/2025 Severity Medium CVE-2025-62423ClipBucket V5 Blind SQL injection in the Admin Panel Exploitation status Public exploit Fix Not confirmed Affected product C clipbucket-v5 Published 10/16/2025 Severity Medium CVE-2025-21624ClipBucket V5 Playlist Cover File Upload to Remote Code Execution Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 01/07/2025 Severity Critical CVE-2025-21623ClipBucket V5 Unauthenticated Template Directory Update to Denial-of-Service Exploitation status Public exploit Fix Not confirmed Affected product C clipbucket-v5 Published 01/07/2025 Severity High CVE-2025-21622ClipBucket V5 Avatar URL Path Traversal to Arbitrary File Delete Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 01/07/2025 Severity High CVE-2024-54135Untrusted Deserialization in ClipBucket-v5 Version 2.0 to 5.5.1 Revision 199 Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 12/06/2024 Severity Critical CVE-2024-54136Untrusted Deserialization in ClipBucket-v5 Version 5.5.1 Revision 199 and Below Exploitation status Public exploit Fix YesAffected product C clipbucket-v5 Published 12/06/2024 Severity Critical