PT-2025-45407 · Unknown · Clipbucket

Published

2025-11-07

·

Updated

2025-12-05

·

CVE-2025-64336

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ClipBucket versions 5.5.2-#146 and below
Description ClipBucket is a video sharing platform. A stored Cross-site Scripting (XSS) issue exists in the Manage Photos feature. An authenticated regular user can upload a photo with a malicious Photo Title containing HTML/JavaScript code. This code is rendered unsafely in the Admin → Manage Photos section, leading to JavaScript execution in the administrator’s browser. The Photo Title is the vulnerable parameter.
Recommendations Update to ClipBucket version 5.5.2-#147.

Exploit

Fix

Improper Privilege Management

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-64336
GHSA-HJC2-5329-J49W

Affected Products

Clipbucket