Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oxygenz

First CVE: Dec 6, 2024Active for: 2 yearsTotal CVEs: 25
51.2
VTI Score
TOP TARGET

Oxygenz maintains a focused but prominently targeted product portfolio centered on ClipBucket, a media-sharing and video-management platform deployed across content-hosting and streaming environments. Despite a narrow product scope, the vendor's vulnerability footprint reaches serious outcomes with an elevated share of disclosures reaching critical severity, and a moderate tendency toward public exploit availability reflects the web-application attack surface and administrative functionality at stake. The recurring exposure pattern spans input-handling weaknesses including cross-site scripting, SQL injection, and path traversal, alongside deserialization flaws and improper privilege management, which are characteristic of large, user-facing PHP-based applications that handle untrusted media and user data. Defenders should treat ClipBucket instances, particularly those internet-reachable or handling sensitive media, as requiring prompt patching; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
8.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oxygenz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2024
19 months ago
Most Recent CVE
Mar 18, 2026
129 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-67418CRITICAL
ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded default administrative credentials. An unauthenticated remo
Dec 22, 20259.835NONO
CVE-2025-55912HIGH
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any aut
Sep 18, 20257.335NOYES
CVE-2026-21875CRITICAL
ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#187 and below allow an attacker to perform Blind SQL Injection through the add comment section within a chan
Jan 8, 20269.834NONO
CVE-2025-55911MEDIUM
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter
Sep 18, 20256.533NOYES
CVE-2026-32321HIGH
ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability exists in ClipBucket prior to 5.5.3 #80 within the `actions/aj
Mar 18, 20268.828NONO
CVE-2025-62709HIGH
ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php causes the application to dynamically build the server URL from t
Nov 20, 20258.828NONO
CVE-2025-64338CRITICAL
ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contai
Nov 7, 20259.027NONO
CVE-2025-21624CRITICAL
ClipBucket V5 provides open source video hosting with PHP. Prior to 5.5.1 - 239, a file upload vulnerability exists in the Manage Playlist functionality of the application, specifi
Jan 7, 20259.827NONO
CVE-2024-54135HIGH
ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are vulnerable to PHP Deserialization vulnerability. The vulnerab
Dec 6, 20248.827NONO
CVE-2024-54136CRITICAL
ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability
Dec 6, 20249.825NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
44%
32%
24%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (96.0%)
High1 (4.0%)
Unknown0 (0.0%)
User Interaction
None18 (72.0%)
Unknown0 (0.0%)
Required7 (28.0%)
Privileges Required
Low11 (44.0%)
High4 (16.0%)
None10 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
8.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oxygenz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oxygenz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oxygenz's Products

View all 2 CNAs →

Top CWEs