Blind SQL Injection Vulnerability in ClipBucket by MacWarrior
CVE-2026-77927
7.1HIGH
What is CVE-2026-77927?
A blind SQL injection risk exists in ClipBucket versions prior to 5.5.3-#182, affecting users with authentication privileges. By manipulating the 'check_photo' parameter, attackers can bypass the 'clean_requests()' sanitization function, allowing unsanitized input to flow into SQL queries. This flaw can be exploited through the bulk deletion handler, enabling adversaries to execute time-based blind SQL injection techniques. As a result, sensitive information such as credential hashes can potentially be retrieved from the database.
Affected Version(s)
clipbucket-v5 0 < 5.5.3-#182
