SQL Injection Vulnerability in ClipBucket Video Sharing Platform
CVE-2026-49482
4.3MEDIUM
What is CVE-2026-49482?
ClipBucket v5, an open-source video sharing platform, contains a vulnerability in its subtitle editing feature that allows an authenticated user to exploit improperly handled SQL wildcard characters. By sending a percentage character (%) as a parameter, the user can overwrite all subtitle titles for any video they own with a single HTTP request. This significant flaw has been resolved in version 5.5.3, ensuring improved security and functionality for users.
Affected Version(s)
clipbucket-v5 < 5.5.3 - #141
