Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profiledesc, aboutme, schools, occupation, companies, hobbies, favmovies, favmusic, favbooks parameters to ProfileSettings page; (2) note parameter to PersonalNotes Section; (3) closedmsg, description, allowedtypes parameters to WebsiteConfigurations Section. NOTE: the collectiondescription vector is already covered by CVE-2015-4673.