CVE-2026-96272
ClipBucket v5 before 5.5.3-#182 SQL Injection via search_result.php
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.
| CWE | CWE-89 |
| Vendor | macwarrior |
| Product | clipbucket-v5 |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for macwarrior clipbucket-v5
Be the first to know when new high vulnerabilities affecting macwarrior clipbucket-v5 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
MacWarrior / clipbucket-v5
0 < 5.5.3-#182
References
github.com: https://github.com/MacWarrior/clipbucket-v5/pull/874 github.com: https://github.com/MacWarrior/clipbucket-v5/commit/7fd0af6f8b5826c2d6ef0976dbb1867f5c36b707 github.com: https://github.com/MacWarrior/clipbucket-v5/blob/57b0235f2eae390f4946c042bf81c182a9f82782/upload/includes/classes/photos.class.php#L408-L413 hackmd.io: https://hackmd.io/@leediay/sqli-photo-seach-clipbucketv5 github.com: https://github.com/MacWarrior/clipbucket-v5 vulncheck.com: https://www.vulncheck.com/advisories/clipbucket-v5-before-5.5.3-182-sql-injection-via-search-result-php
Credits
leediay153