CVE-2026-95812
ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can craft malicious requests with injected script payloads in these parameters to execute arbitrary JavaScript in victims' browsers under the application origin.
| CWE | CWE-79 |
| Vendor | macwarrior |
| Product | clipbucket-v5 |
| Published | Sep 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for macwarrior clipbucket-v5
Be the first to know when new medium vulnerabilities affecting macwarrior clipbucket-v5 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
MacWarrior / clipbucket-v5
0 < 5.5.3-#182
References
github.com: https://github.com/MacWarrior/clipbucket-v5/commit/032f46937e091e22afa6c99f2c888575cc94e44b github.com: https://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.3-%23182 github.com: https://github.com/MacWarrior/clipbucket-v5/blob/5.5.3-%23153/upload/includes/functions.php hackmd.io: https://hackmd.io/@leediay/reflected-xss-in-search-function-clipbucket-v5 github.com: https://github.com/MacWarrior/clipbucket-v5 vulncheck.com: https://www.vulncheck.com/advisories/clipbucket-v5-before-5.5.3-182-reflected-xss-via-query-parameters
Credits
leediay153