ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contains HTML/JavaScript payloads, which making ClipBucket’s Manage Photos feature vulnerable to Stored XSS. The payload is rendered unsafely in the Admin → Manage Photos interface, causing it to execute in the administrator’s browser, therefore allowing an attacker to target administrators and perform actions with elevated privileges. This issue is fixed in version 5.5.2 - #157.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This CVE is a duplicate of another CVE. | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contains HTML/JavaScript payloads, which making ClipBucket’s Manage Photos feature vulnerable to Stored XSS. The payload is rendered unsafely in the Admin → Manage Photos interface, causing it to execute in the administrator’s browser, therefore allowing an attacker to target administrators and perform actions with elevated privileges. This issue is fixed in version 5.5.2 - #157. |
| Title | ClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection Name | |
| Weaknesses | CWE-269 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Fri, 07 Nov 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This CVE is a duplicate of another CVE. |
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-15T22:55:03.488Z
Updated: 2025-12-16T15:09:59.194Z
Reserved: 2025-10-30T17:40:52.030Z
Link: CVE-2025-64338
Updated: 2025-12-16T14:38:23.490Z
Status : Awaiting Analysis
Published: 2025-11-07T05:16:10.167
Modified: 2025-12-16T14:10:24.660
Link: CVE-2025-64338
No data.