Oxygenz maintains a focused but prominently targeted product portfolio centered on ClipBucket, a media-sharing and video-management platform deployed across content-hosting and streaming environments. Despite a narrow product scope, the vendor's vulnerability footprint reaches serious outcomes with an elevated share of disclosures reaching critical severity, and a moderate tendency toward public exploit availability reflects the web-application attack surface and administrative functionality at stake. The recurring exposure pattern spans input-handling weaknesses including cross-site scripting, SQL injection, and path traversal, alongside deserialization flaws and improper privilege management, which are characteristic of large, user-facing PHP-based applications that handle untrusted media and user data. Defenders should treat ClipBucket instances, particularly those internet-reachable or handling sensitive media, as requiring prompt patching; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oxygenz over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67418CRITICAL ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remo | Dec 22, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-55912HIGH An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any aut | Sep 18, 2025 | 7.3 | 35 | NO | YES |
CVE-2026-21875CRITICAL ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the add comment section within a chan | Jan 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-55911MEDIUM An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter | Sep 18, 2025 | 6.5 | 33 | NO | YES |
CVE-2026-32321HIGH ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5.5.3 #80 within the `actions/aj | Mar 18, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-62709HIGH ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server URL from t | Nov 20, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-64338CRITICAL ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contai | Nov 7, 2025 | 9.0 | 27 | NO | NO |
CVE-2025-21624CRITICAL ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifi | Jan 7, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-54135HIGH ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are vulnerable to PHP Deserialization vulnerability. The vulnerab | Dec 6, 2024 | 8.8 | 27 | NO | NO |
CVE-2024-54136CRITICAL ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability | Dec 6, 2024 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oxygenz.
Media articles that mention a CVE ID that affects a product developed by Oxygenz — matched by CVE ID, not by vendor name.