PT-2025-38416 · Unknown · Clipbucket

Mukund.S1337

·

Published

2025-09-18

·

Updated

2025-09-19

·

CVE-2025-55912

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions ClipBucket versions prior to 5.5.0
Description An issue exists in ClipBucket that allows an unauthenticated attacker to upload arbitrary files via the photo uploader.php plupload endpoint due to missing access controls in the upload handler.
Recommendations Update ClipBucket to a version newer than 5.5.0.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-55912

Affected Products

Clipbucket