CVE 9.8 CRITICAL

ClipBucket: Blind SQL Injection in progress_video.php_CVE-2026-45060

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129.

AI Analysis

Blind SQL injection vulnerability in the actions/progress_video.php endpoint, allowing unauthenticated users to execute SQL queries and exfiltrate sensitive data.

Basic Information

ID CVE-2026-45060
Source GitHub_M
Published Jun 11, 2026 at 22:51

Affected Product

Vendor MacWarrior
Product clipbucket-v5
Version < 5.5.3 - #129
Affected Versions MacWarrior clipbucket-v5 < 5.5.3 - #129

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor MacWarrior
Product ClipBucket
Version < 5.5.3 - #129

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.