Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/clipbucket-v5

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

ClipBucket v5 through version 5.5.3-#197 contains a high-severity SQL injection vulnerability. Authenticated users with ad_manager_access permission can exploit this flaw by injecting SQL commands via the delete parameter in the ads_manager.php admin interface. This allows attackers to perform time-based blind SQL injection attacks to extract sensitive data such as user credentials and emails or to modify and delete arbitrary database records.

Join the discussion

ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function. This flaw allows an authenticated administrator with basic_settings permission to inject arbitrary SQL commands via the language_id parameter, which is not properly escaped in an UPDATE statement's WHERE clause. The vulnerability can be exploited to extract or modify database contents.

Join the discussion

ClipBucket v5 through 5.5.3-#197 has a time-based blind SQL injection vulnerability in its admin video edit function. This flaw allows an authenticated administrator with video_moderation permission to inject arbitrary SQL commands via the videoid parameter, which is improperly escaped in an UPDATE statement.

Join the discussion

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web server user.

Join the discussion

ClipBucket v5 before 5.5.3-#182 has a blind SQL injection vulnerability in its photo search endpoint. The vulnerability arises because a query parameter is unsanitized and used directly in SQL WHERE and ORDER BY clauses. This allows unauthenticated attackers to perform time-based blind SQL injection attacks to extract sensitive information such as user credentials, email addresses, and administrator password hashes, potentially leading to account takeover.

Join the discussion

ClipBucket v5 before 5.5.3-#182 has a reflected cross-site scripting (XSS) vulnerability in the sort_link() helper function. This flaw occurs because the cat, sort, and time query parameters are not properly sanitized, allowing attackers to inject malicious JavaScript payloads. Successful exploitation could lead to arbitrary script execution in users' browsers within the context of the affected application.

Join the discussion

ClipBucket v5 before 5.5.3-#182 has a file upload vulnerability that allows authenticated users to upload PHP files disguised as images. This leads to remote code execution because the file extension is not properly updated after MIME validation, allowing PHP code execution via PHP-FPM.

Join the discussion

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all user credential hashes and email addresses.

Join the discussion

ClipBucket v5 before 5.5.3-#182 has a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database data. The flaw arises from improper sanitization of the check_photo parameter when submitted as an array, bypassing the clean_requests() function. Unsanitized inputs reach SQL queries in photos.class.php, enabling time-based blind SQL injection attacks to retrieve sensitive information such as credential hashes.

Join the discussion

ClipBucket V5 version 5.5.1 contains an OS command injection vulnerability in its web installer. The vulnerability arises because the php_cli_filepath parameter is not properly validated or escaped before being passed to shell execution. This allows unauthenticated attackers to execute arbitrary commands as the web server user by submitting a crafted POST request to the installer. The vulnerability has a critical severity with a CVSS score of 9.2.

Join the discussion

Showing 1 to 10 of 27 results

Filters:Package: pkg:github/clipbucket-v5
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses