CVE-2025-62424Medium· 6.7▾ SunlitClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of the file-loading path is inadequate, allowi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/template_editor.php endpoint is vulnerable to path traversal. The validation of the file-loading path is inadequate, allowing authenticated administrators to read and write arbitrary files outside the intended template directory by inserting path traversal sequences into the folder parameter. An attacker with administrator privileges can exploit this vulnerability to read sensitive files such as /etc/passwd and modify writable files on the system, potentially leading to sensitive information disclosure and compromise of the application or server. This issue is fixed in version 5.5.2 - #147.
clipbucket >= 5.3, < 5.5.2-147Upgrade past the affected range:
clipbucket 5.5.2-147Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62423Medium· 6.7ClipBucket V5 provides open source video hosting with PHP
CVE-2025-62429High· 7.2ClipBucket v5 is an open source video sharing platform
CVE-2025-62430Medium· 5.4ClipBucket v5 is an open source video sharing platform
CVE-2025-64114Medium· 6.5ClipBucket v5 is an open source video sharing platform
CVE-2025-65113Medium· 6.5ClipBucket v5 is an open source video sharing platform
CVE-2025-64338Critical· 9.0ClipBucket v5 is an open source video sharing platform