---
id: CVE-2025-64338
title: ClipBucket v5 is an open source video sharing platform
summary: >-
  ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 -
  #156 and below, an authenticated regular user can create a photo collection
  whose Collection Name contains HTML/JavaScript payloads, which making
  ClipBucket’s Ma…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-79
  - CWE-269
  - CWE-79
vendor: oxygenz
product: clipbucket
affected:
  - 'clipbucket >= 5.3, < 5.5.2-157'
patched:
  - clipbucket 5.5.2-157
published: '2025-11-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64338'
references:
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/commit/8e3cf79ce2721fbebde68a05a9a1a6319f086bcc
    label: security-advisories@github.com
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-93rh-fxxx-j38j
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00493
epssPercentile: 0.40028
ingestedAt: '2026-09-30T23:29:32.463Z'
---

## Overview

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contains HTML/JavaScript payloads, which making ClipBucket’s Manage Photos feature vulnerable to Stored XSS. The payload is rendered unsafely in the Admin → Manage Photos interface, causing it to execute in the administrator’s browser, therefore allowing an attacker to target administrators and perform actions with elevated privileges. This issue is fixed in version 5.5.2 - #157.

## Affected

- `clipbucket >= 5.3, < 5.5.2-157`

## Remediation

Upgrade past the affected range:

- `clipbucket 5.5.2-157`
