CVE-2026-26997: ClipBucket v5 has Stored XSS via Collection name
Published Feb 27, 2026
·Updated
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can store the XSS payload. The payload is triggered by administrator. Version 5.5.3 #59 fixes the issue.
Affected Software
2 affected components
ClipBucket ClipBucket<5.5.3
Oxygenz Clipbucket>=5.3<5.5.3-59
Remediation
Event History
Feb 27, 2026
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionWeakness
Data Sourced
via NVD·08:21 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 24, 58140
Event
via NVD·04:05 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-26997?
CVE-2026-26997 is classified as a high severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2026-26997?
To fix CVE-2026-26997, upgrade ClipBucket to version 5.5.3 or later.
3
Who is affected by CVE-2026-26997?
Authenticated users of ClipBucket prior to version 5.5.3 are affected by CVE-2026-26997.
4
What kind of attack does CVE-2026-26997 enable?
CVE-2026-26997 enables stored cross-site scripting (XSS) attacks that can be triggered by an administrator.
5
What software versions are vulnerable to CVE-2026-26997?
ClipBucket versions earlier than 5.5.3 are vulnerable to CVE-2026-26997.