PT-2026-26155 · Macwarrior · Clipbucket-V5

Published

2026-03-18

·

Updated

2026-03-18

·

CVE-2026-32321

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5.5.3 #80 within the actions/ajax.php endpoint. Due to insufficient input sanitization of the userid parameter, an authenticated attacker can execute arbitrary SQL queries, leading to full database disclosure and potential administrative account takeover. Version 5.5.3 #80 fixes the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-32321

Affected Products

Clipbucket-V5