Description
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data theft via blind SQL injection on authenticated users
Action: Immediate Patch
AI Analysis

Impact

ClipBucket v5 prior to release 5.5.3‑#182 contains a blind SQL injection flaw in the photo deletion endpoint. The vulnerability allows an authenticated user to submit an array value for the check_photo parameter, which bypasses the internal clean_requests() sanitisation routine. The unsanitised array elements reach the photo_exists() routine, where non‑numeric values are interpolated directly into a SQL query, enabling time‑based blind injection. Attackers can therefore extract arbitrary database contents, including credential hashes and other sensitive data, without needing to exploit the application in a user‑friendly manner.

Affected Systems

The flaw affects installations of ClipBucket v5 from MacWarrior, specifically versions earlier than 5.5.3‑#182. Any system running this version and allowing authenticated users to access the bulk deletion handler in manage_photos.php is at risk. No other products or versions have been identified as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity data‑exfiltration risk. The EPSS score of 0.00406 indicates a very low likelihood of immediate exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated access to the photo deletion endpoint, which is likely restricted to registered users. Once accessed, an attacker can inject arbitrary arrays to perform blind SQLi, exploiting the lack of parameterised queries and allowing information disclosure. The absence of a public exploit does not reduce the need for a timely update because the conditions for exploitation are realistic and the impact is significant.

Generated by OpenCVE AI on September 19, 2026 at 19:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ClipBucket to version 5.5.3‑#182 or later to remove the unsanitised array handling.
  • Disable or restrict the bulk photo deletion feature for non‑admin users until a patch is applied.
  • Audit database credentials and remove unnecessary read privileges for the application account to minimise data exposure if the injection is successful.

Generated by OpenCVE AI on September 19, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Oxygenz
Oxygenz clipbucket
CPEs cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:*
Vendors & Products Oxygenz
Oxygenz clipbucket

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Macwarrior
Macwarrior clipbucket-v5
Vendors & Products Macwarrior
Macwarrior clipbucket-v5

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description ClipBucket v5 through 5.5.3 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data. ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data.
Title ClipBucket 5.5.3 Blind SQL Injection via Photo Deletion Endpoint ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description ClipBucket v5 through 5.5.3 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data.
Title ClipBucket 5.5.3 Blind SQL Injection via Photo Deletion Endpoint
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Macwarrior Clipbucket-v5
Oxygenz Clipbucket
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T19:19:29.515Z

Reserved: 2026-08-21T17:52:36.079Z

Link: CVE-2026-77927

cve-icon Vulnrichment

Updated: 2026-09-18T17:52:13.058Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T15:17:12.987

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-77927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')