Ad

CVE-2025-64338

CRITICAL CVSS 3.1: 9.0 EPSS 0.04%
Updated Dec 31, 2025
Oxygenz
Parameter Value
CVSS 9.0 (CRITICAL)
Affected Versions 5.3 — 5.5.2-157
Fixed In 5.5.2
Type CWE-79 (Cross-Site Scripting (XSS)), CWE-269 (Improper Privilege Management)
Vendor Oxygenz
Public PoC No

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contains HTML/JavaScript payloads, which making ClipBucket’s Manage Photos feature vulnerable to Stored XSS. The payload is rendered unsafely in the Admin → Manage Photos interface, causing it to execute in the administrator’s browser, therefore allowing an attacker to target administrators and perform actions with elevated privileges.

This issue is fixed in version 5.5.2 - #157.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Oxygenz Clipbucket
cpe:2.3:a:oxygenz:clipbucket:*:*:*:*:*:*:*:*
5.3 5.5.2-157