CVE-2025-64338 MEDIUM

CVE-2025-64338: ClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection Name

Vendor Macwarrior
Product clipbucket-v5
Weakness CWE-79 · XSS
Published December 15, 2025
Last update December 16, 2025

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contains HTML/JavaScript payloads, which making ClipBucket’s Manage Photos feature vulnerable to Stored XSS. The payload is rendered unsafely in the Admin → Manage Photos interface, causing it to execute in the administrator’s browser, therefore allowing an attacker to target administrators and perform actions with elevated privileges. This issue is fixed in version 5.5.2 - #157.

Key dates

02Disclosure timeline

December 15, 2025 CVE published
December 16, 2025 Record updated