vciy

CVEs we hold for Macwarrior

Records whose assigning authority named Macwarrior as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-80138ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath ParameterMacWarrior clipbucket-v5
CVE-2026-77929ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload EndpointMacWarrior clipbucket-v5
CVE-2026-77928ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion EndpointMacWarrior clipbucket-v5
CVE-2026-77927ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion EndpointMacWarrior clipbucket-v5
CVE-2026-49482ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle OverwriteMacWarrior clipbucket-v5
CVE-2026-47238ClipBucket: IDOR in videos subtitle editorMacWarrior clipbucket-v5
CVE-2026-45418ClipBucket: Blind SQL Injection in subtitle_edit.phpMacWarrior clipbucket-v5
CVE-2026-45060ClipBucket: Blind SQL Injection in progress_video.phpMacWarrior clipbucket-v5
CVE-2026-42847ClipBucket: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')MacWarrior clipbucket-v5
CVE-2026-42846ClipBucket: Remote Play URL Command InjectionMacWarrior clipbucket-v5
CVE-2026-32321ClipBucket v5 has time-based Blind SQL Injection in ajax.php that leads to Data ExfiltrationMacWarrior clipbucket-v5
CVE-2026-28354ClipBucket v5 has IDOR in Collection Item ManagementMacWarrior clipbucket-v5
CVE-2026-26997ClipBucket v5 has Stored XSS via Collection nameMacWarrior clipbucket-v5
CVE-2026-26005ClipBucket v5 enables internal network scans via an SSRF vulnerabilityMacWarrior clipbucket-v5
CVE-2026-25728ClipBucket v5 Affected by Remote Code Execution via Avatar/Background File Upload Race ConditionMacWarrior clipbucket-v5
CVE-2026-21875ClipBucket v5 Vulnerable to Blind SQL Injection through Channel CommentsMacWarrior clipbucket-v5
CVE-2025-65113ClipBucket v5 Unauthenticated Object Flagging VulnerabilityMacWarrior clipbucket-v5
CVE-2025-64339ClipBucket v5: Stored XSS Vulnerability in Manage PlaylistsMacWarrior clipbucket-v5
CVE-2025-64338ClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection NameMacWarrior clipbucket-v5
CVE-2025-64336ClipBucket v5's Manage Photo Feature is Vulnerable to Stored XSS Attack via Photo TitleMacWarrior clipbucket-v5
CVE-2025-64114ClipBucket v5: SQL Injection possible through ClipBucket Custom Fields pluginMacWarrior clipbucket-v5
CVE-2025-62715ClipBucket v5: Stored XSS via Collection TagsMacWarrior clipbucket-v5
CVE-2025-62709ClipBucket v5 is vulnerable to password reset link manipulationMacWarrior clipbucket-v5
CVE-2025-62430ClipBucket v5 stored XSS via video/photo fieldsMacWarrior clipbucket-v5
CVE-2025-62429ClipBucket v5 executes arbitrary PHP codeMacWarrior clipbucket-v5
CVE-2025-62424ClipBucket path traversal vulnerability in template editor allows arbitrary file read and writeMacWarrior clipbucket-v5
CVE-2025-62423ClipBucket V5 Blind SQL injection in the Admin PanelMacWarrior clipbucket-v5
CVE-2025-21624ClipBucket V5 Playlist Cover File Upload to Remote Code ExecutionMacWarrior clipbucket-v5
CVE-2025-21623ClipBucket V5 Unauthenticated Template Directory Update to Denial-of-ServiceMacWarrior clipbucket-v5
CVE-2025-21622ClipBucket V5 Avatar URL Path Traversal to Arbitrary File DeleteMacWarrior clipbucket-v5
CVE-2024-54136Untrusted Deserialization in ClipBucket-v5 Version 5.5.1 Revision 199 and BelowMacWarrior clipbucket-v5
CVE-2024-54135Untrusted Deserialization in ClipBucket-v5 Version 2.0 to 5.5.1 Revision 199MacWarrior clipbucket-v5

32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.