CVE-2026-96272
published 2026-09-23CVE-2026-96272: ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.32%
23.0th percentile
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| macwarrior | clipbucket-v5 | < 5.5.3-#182 | 5.5.3-#182 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MacWarrior ClipBucket up to 5.5.3-#181 Photo Search Endpoint Query sql injection
vuldb·2026-09-23·CVSS 7.5
CVE-2026-96272 [HIGH] MacWarrior ClipBucket up to 5.5.3-#181 Photo Search Endpoint Query sql injection
A vulnerability described as critical has been identified in MacWarrior ClipBucket up to 5.5.3-#181. Impacted is an unknown function of the component Photo Search Endpoint. The manipulation of the argument Query results in sql injection.
This vulnerability was named CVE-2026-96272. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses.
ghsa_unreviewed·2026-09-23
CVE-2026-96272 [HIGH] CWE-89 ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses.
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/MacWarrior/clipbucket-v5https://github.com/MacWarrior/clipbucket-v5/blob/57b0235f2eae390f4946c042bf81c182a9f82782/upload/includes/classes/photos.class.php#L408-L413https://github.com/MacWarrior/clipbucket-v5/commit/7fd0af6f8b5826c2d6ef0976dbb1867f5c36b707https://github.com/MacWarrior/clipbucket-v5/pull/874https://hackmd.io/@leediay/sqli-photo-seach-clipbucketv5https://www.vulncheck.com/advisories/clipbucket-v5-before-5.5.3-182-sql-injection-via-search-result-phphttps://hackmd.io/@leediay/sqli-photo-seach-clipbucketv5
2026-09-23
Published