---
id: CVE-2026-95812
title: >-
  ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting
  vulnerability in the sort_link() helper function that fails to sanitize cat,
  sort, and time query parameters
summary: >-
  ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting
  vulnerability in the sort_link() helper function that fails to sanitize cat,
  sort, and time query parameters. Attackers can craft malicious requests with
  injected …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: MacWarrior
product: clipbucket-v5
affected:
  - clipbucket-v5 < 5.5.3-#182
published: '2026-09-22'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95812'
references:
  - url: 'https://github.com/MacWarrior/clipbucket-v5'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/blob/5.5.3-%23153/upload/includes/functions.php
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/MacWarrior/clipbucket-v5/commit/032f46937e091e22afa6c99f2c888575cc94e44b
    label: disclosure@vulncheck.com
  - url: 'https://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.3-%23182'
    label: disclosure@vulncheck.com
  - url: 'https://hackmd.io/@leediay/reflected-xss-in-search-function-clipbucket-v5'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/clipbucket-v5-before-5.5.3-182-reflected-xss-via-query-parameters
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00354
epssPercentile: 0.26402
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T15:39:05.323788Z'
ingestedAt: '2026-09-22T21:11:40.326Z'
---

## Overview

ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can craft malicious requests with injected script payloads in these parameters to execute arbitrary JavaScript in victims' browsers under the application origin.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
