Skip to main content

Vendor archive

clip-bucket CVEs

Beta · best-effort

14 CVEs tagged to vendor clip-bucket4 Critical, 3 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2013-10040

Published Jul 31, 2025

ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenti…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-7666

Published Mar 5, 2018

An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php e…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-7665

Published Mar 5, 2018

An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.php or actions/photo_uploader.ph…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-7664

Published Mar 5, 2018

An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1000307

Published Apr 6, 2017

Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, abo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4673

Published Apr 6, 2017

Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the collection_descriptio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4848

Published Sep 2, 2016

Cross-site scripting (XSS) vulnerability in ClipBucket before 2.8.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5849

Published May 14, 2015

Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in an add_frie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2102

Published Feb 27, 2015

SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4187

Published Jun 17, 2014

Cross-site scripting (XSS) vulnerability in signup.php in ClipBucket allows remote attackers to inject arbitrary web script or HTML via the Username field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6644

Published Apr 8, 2014

Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6643

Published Apr 8, 2014

Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6642

Published Apr 8, 2014

Cross-site scripting (XSS) vulnerability in ClipBucket 2.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter to view_channel.php. NOTE: the pr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3717

Published Sep 23, 2011

ClipBucket 2.0.9 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1