๐Ÿ” CVE Alert

CVE-2026-95812

MEDIUM 6.1

ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can craft malicious requests with injected script payloads in these parameters to execute arbitrary JavaScript in victims' browsers under the application origin.

CWE CWE-79
Vendor macwarrior
Product clipbucket-v5
Published Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for macwarrior clipbucket-v5

Be the first to know when new medium vulnerabilities affecting macwarrior clipbucket-v5 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

MacWarrior / clipbucket-v5
0 < 5.5.3-#182

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MacWarrior/clipbucket-v5/commit/032f46937e091e22afa6c99f2c888575cc94e44b github.com: https://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.3-%23182 github.com: https://github.com/MacWarrior/clipbucket-v5/blob/5.5.3-%23153/upload/includes/functions.php hackmd.io: https://hackmd.io/@leediay/reflected-xss-in-search-function-clipbucket-v5 github.com: https://github.com/MacWarrior/clipbucket-v5 vulncheck.com: https://www.vulncheck.com/advisories/clipbucket-v5-before-5.5.3-182-reflected-xss-via-query-parameters

Credits

leediay153