Stored XSS Vulnerability in ClipBucket Video Sharing Platform
CVE-2025-62715
5.3MEDIUM
What is CVE-2025-62715?
ClipBucket, an open source video sharing platform, is affected by a stored Cross-Site Scripting vulnerability in its Collection tags feature. An authenticated user can input HTML or JavaScript in tags, which then renders unescaped in both collection detail and tag-list pages. This allows for the execution of arbitrary JavaScript in the browsers of any user who views the affected pages, posing significant security risks. The issue has been addressed in version 5.5.2-#152.
Affected Version(s)
clipbucket-v5 < 5.5.2-#152
