CVE-2026-96272: ClipBucket v5 before 5.5.3-#182 SQL Injection via search_result.php

Published Sep 23, 2026
·
Updated

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.

Affected Software

1 affected component
ClipBucket ClipBucket<5.5.3-#182

Event History

Sep 23, 2026
CVE Published
via MITRE·12:29 AM
Data Sourced
via MITRE·12:29 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any unauthenticated remote attacker can target the affected photo search endpoint. No account or user interaction is required.

2

What information could be exposed?

An attacker can use time-based blind SQL injection to extract user credentials, email addresses, and administrator password hashes. Exposed administrator hashes could enable account takeover.

3

Are installations before the fixed release affected by default?

The affected functionality is the photo search endpoint in ClipBucket v5 before 5.5.3-#182. The provided data does not state whether that endpoint must be separately enabled or configured.

4

How can I determine whether my instance is vulnerable?

Check whether the deployment runs ClipBucket v5 earlier than 5.5.3-#182 and exposes the photo search endpoint. The issue involves unsanitized query input reaching SQL WHERE and ORDER BY clauses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203