SQL Injection Vulnerability in ClipBucket Video Sharing Platform
CVE-2026-42847
7.1HIGH
What is CVE-2026-42847?
ClipBucket, an open-source video sharing platform, has a SQL Injection vulnerability that allows attackers to exploit the authenticated admin endpoint. The flaw arises in the admin_area/action_logs.php file, where an unparameterized user input is directly concatenated into a SQL query, enabling UNION-based SQL injection attacks. This can result in unauthorized data alteration or extraction from the database. This vulnerability has been addressed in version 5.5.3.
Affected Version(s)
clipbucket-v5 < 5.5.3 - #122
