ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws, allowing a normal authenticated user to modify another user’s collection items. This affects both add item (/actions/add_to_collection.php) due to missing authorization checks and delete item (/manage_collections.php?mode=manage_items...) due to a broken ownership check in removeItemFromCollection(). As a result, attackers can insert and remove items from collections they do not own. Version 5.5.3 #59 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oxygenz
Oxygenz clipbucket |
|
| CPEs | cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oxygenz
Oxygenz clipbucket |
|
| Metrics |
cvssV3_1
|
Mon, 02 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Macwarrior
Macwarrior clipbucket-v5 |
|
| Vendors & Products |
Macwarrior
Macwarrior clipbucket-v5 |
Fri, 27 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws, allowing a normal authenticated user to modify another user’s collection items. This affects both add item (/actions/add_to_collection.php) due to missing authorization checks and delete item (/manage_collections.php?mode=manage_items...) due to a broken ownership check in removeItemFromCollection(). As a result, attackers can insert and remove items from collections they do not own. Version 5.5.3 #59 fixes the issue. | |
| Title | ClipBucket v5 has IDOR in Collection Item Management | |
| Weaknesses | CWE-639 CWE-863 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-27T19:18:25.500Z
Updated: 2026-02-27T20:23:22.876Z
Reserved: 2026-02-26T18:38:13.890Z
Link: CVE-2026-28354
Updated: 2026-02-27T20:23:17.086Z
Status : Analyzed
Published: 2026-02-27T20:21:40.883
Modified: 2026-03-03T20:08:50.290
Link: CVE-2026-28354
No data.