PT-2025-45168 · Clipbucket+1 · Clipbucket Custom Fields Plugin+1

Published

2025-11-05

·

Updated

2025-11-10

·

CVE-2025-64114

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ClipBucket versions 5.5.2 and below
Description ClipBucket v5 is a video sharing platform. Versions 5.5.2 and below allow authenticated administrators with plugin management privileges to execute arbitrary SQL commands against the database through the ClipBucket Custom Fields plugin. Exploitation requires the Custom Fields plugin to be installed and accessible, and is limited to users with administrative access to the plugin interface. The vulnerable component is the ClipBucket Custom Fields plugin.
Recommendations Versions prior to 5.5.2 should be updated to version 5.5.2 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-64114
GHSA-4G7X-J562-8G69

Affected Products

Clipbucket
Clipbucket Custom Fields Plugin