Clip Bucket is a video sharing and streaming platform with a modest vulnerability footprint concentrated in its core product. The recurring disclosures reflect the attack surface of a web-based media application handling user uploads, content delivery, and access control. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clip Bucket over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7665CRITICAL An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.php or actions/photo_uploader.php | Mar 5, 2018 | 9.8 | 48 | NO | YES |
CVE-2013-10040CRITICAL ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthentic | Jul 31, 2025 | 9.8 | 42 | NO | YES |
CVE-2015-2102HIGH SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter. | Feb 27, 2015 | 7.5 | 36 | NO | YES |
CVE-2012-5849HIGH Multiple SQL injection vulnerabilities in ClipBucket 2.6 Revision 738 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) uid parameter in an add_frien | May 14, 2015 | 7.5 | 35 | NO | YES |
CVE-2012-6643HIGH Multiple SQL injection vulnerabilities in the update_counter function in includes/functions.php in ClipBucket 2.6 allow remote attackers to execute arbitrary SQL commands via the t | Apr 8, 2014 | 7.5 | 33 | NO | YES |
CVE-2018-7664CRITICAL An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /a | Mar 5, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-7666CRITICAL An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php em | Mar 5, 2018 | 9.8 | 28 | NO | NO |
CVE-2012-6644MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to channels.php, (2) c | Apr 8, 2014 | 4.3 | 26 | NO | YES |
CVE-2016-1000307MEDIUM Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, abou | Apr 6, 2017 | 6.1 | 22 | NO | NO |
CVE-2016-4848MEDIUM Cross-site scripting (XSS) vulnerability in ClipBucket before 2.8.1 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Sep 2, 2016 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clip Bucket.
Media articles that mention a CVE ID that affects a product developed by Clip Bucket — matched by CVE ID, not by vendor name.