CVE-2025-62715: ClipBucket v5: Stored XSS via Collection Tags
ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Scripting (XSS) vulnerability in ClipBucket’s Collection tags feature. An authenticated normal user can create a tag containing HTML or JavaScript, which is later rendered unescaped in collection detail and tag-list pages. As a result, arbitrary JavaScript executes in the browsers of all users who view the affected pages. This issue is fixed in version 5.5.2-#152.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62715?
CVE-2025-62715 is classified as a medium severity vulnerability due to its stored Cross-Site Scripting (XSS) nature.
How do I fix CVE-2025-62715?
To fix CVE-2025-62715, upgrade ClipBucket to version 5.5.2-#148 or above, which addresses the XSS vulnerability.
Who is affected by CVE-2025-62715?
Authenticated normal users of ClipBucket versions 5.5.2-#147 and below are affected by CVE-2025-62715.
What type of vulnerability is CVE-2025-62715?
CVE-2025-62715 is a stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2025-62715 be exploited remotely?
Yes, CVE-2025-62715 can be exploited remotely by authenticated users who can create malicious tags.