CVE-2026-77927: ClipBucket 5.5.3 Blind SQL Injection via Photo Deletion Endpoint

Published Sep 18, 2026
·
Updated

ClipBucket v5 through 5.5.3 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the checkphoto parameter as an array to bypass the cleanrequests() sanitization function in ClipBucket.class.php. Attackers can pass unsanitized array elements through the bulk deletion handler in managephotos.php to photoexists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to retrieve credential hashes and other sensitive data.

Affected Software

1 affected component
ClipBucket ClipBucket>=5<=5.5.3

Event History

Sep 18, 2026
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The attacker must be authenticated with an account that can reach the photo-deletion functionality. No user interaction is required once the attacker has that access.

2

What data could be exposed through exploitation?

An attacker can use time-based blind SQL injection to extract arbitrary database data, including credential hashes and other sensitive information.

3

Which product versions are identified as affected?

ClipBucket v5 through 5.5.3 are identified as affected by the provided information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203