CVE-2026-45060: ClipBucket: Blind SQL Injection in progress_video.php
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progressvideo.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ClipBucketto a version that resolves this vulnerability.Fixed in 5.5.3 - #129
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45060?
CVE-2026-45060 has a critical severity rating of 9.8.
How do I fix CVE-2026-45060?
To fix CVE-2026-45060, update ClipBucket to version 5.5.3 or later.
What types of data can be exfiltrated through CVE-2026-45060?
Through CVE-2026-45060, an attacker can exfiltrate sensitive data from the database via SQL injections.
Who can exploit the CVE-2026-45060 vulnerability?
Any unauthenticated user can exploit the CVE-2026-45060 vulnerability.
Which component of ClipBucket is affected by CVE-2026-45060?
CVE-2026-45060 affects the actions/progress_video.php endpoint in ClipBucket prior to version 5.5.3.