SQL Injection Vulnerability in ClipBucket Open Source Video Platform
CVE-2026-32321
8.8HIGH
What is CVE-2026-32321?
An authenticated time-based blind SQL injection vulnerability exists in the ClipBucket platform before version 5.5.3 #80. This flaw is due to inadequate sanitization of the 'userid' parameter in the actions/ajax.php endpoint. An attacker with valid credentials can exploit this vulnerability to execute unauthorized SQL commands, potentially leading to a complete database disclosure and the risk of gaining administrative control over affected systems. This issue is addressed in version 5.5.3 #80.
Affected Version(s)
clipbucket-v5 < 5.5.3 - #80
