CVE-2026-96272

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.

Published
September 23, 2026 1:16 AM
Last Modified
September 23, 2026 1:16 AM
Source
[email protected]

Weaknesses (CWE)

CWE-89

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.