Blind SQL Injection Vulnerability in ClipBucket by MacWarrior
CVE-2026-45060

9.8CRITICAL

Key Information:

Vendor

Macwarrior

Vendor
CVE Published:
11 June 2026

What is CVE-2026-45060?

The ClipBucket platform, an open source video sharing solution, is affected by a significant blind SQL injection vulnerability in the actions/progress_video.php endpoint. This flaw allows unauthenticated users to exploit the 'ids' parameter to execute arbitrary SQL queries on the database, thereby potentially exposing sensitive information. The vulnerability has been resolved in version 5.5.3. It is crucial for users to update their installations to ensure their systems remain secure.

Affected Version(s)

clipbucket-v5 < 5.5.3 - #129

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.