Description
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all user credential hashes and email addresses.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Breach (credential theft)
Action: Immediate Patch
AI Analysis

Impact

ClipBucket v5 releases before 5.5.3-#182 contain a blind SQL injection that can be triggered through the private message deletion endpoint. An authenticated user can submit the msg_id parameter as an array to bypass the clean_requests() sanitization, and the unescaped array element is placed directly into a SQL query by the delete_msg() method. The vulnerability allows time‑based blind SQL injection, enabling extraction of any data stored in the database such as user credential hashes and email addresses.

Affected Systems

It affects the ClipBucket v5 platform distributed by MacWarrior, specifically all installations running versions earlier than 5.5.3‑#182. The vulnerable code resides in private_message.php and ClipBucket.class.php. No other products or vendors are listed.

Risk and Exploitability

The CVSS score of 7.1 reflects a medium‑high severity risk for the affected systems, with an EPSS score of <1% and no listing in the CISA KEV catalog. Exploitation requires a valid authenticated session, so attackers with access to a user account or compromised credentials can launch the attack. The injection occurs through a legitimate deletion API, making it hard to detect and potentially allowing full database compromise over time. Because the exploit relies on authenticated users, an internal or compromised user can serve as the entry point.

Generated by OpenCVE AI on September 19, 2026 at 19:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade ClipBucket to version 5.5.3‑#182 or later, which removes the array processing bug in the message deletion endpoint.
  • If an upgrade is not immediately possible, restrict the private_message.php deletion functionality to administrative users only or disable private messaging altogether until a patch is applied.
  • Monitor database activity for unusual query patterns and enforce argument validation to prevent array values in SQL parameters.

Generated by OpenCVE AI on September 19, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Oxygenz
Oxygenz clipbucket
CPEs cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:*
Vendors & Products Oxygenz
Oxygenz clipbucket

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Macwarrior
Macwarrior clipbucket-v5
Vendors & Products Macwarrior
Macwarrior clipbucket-v5

Fri, 18 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description ClipBucket v5 through 5.5.3 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all user credential hashes and email addresses. ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all user credential hashes and email addresses.
Title ClipBucket 5.5.3 Blind SQL Injection via Private Message Deletion Endpoint ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description ClipBucket v5 through 5.5.3 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all user credential hashes and email addresses.
Title ClipBucket 5.5.3 Blind SQL Injection via Private Message Deletion Endpoint
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Macwarrior Clipbucket-v5
Oxygenz Clipbucket
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T19:19:30.198Z

Reserved: 2026-08-21T17:52:36.079Z

Link: CVE-2026-77928

cve-icon Vulnrichment

Updated: 2026-09-22T14:30:07.034Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T15:17:13.143

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-77928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')