PT-2026-48794 · Unknown · Clipbucket-V5

CVE-2026-49482

·

Published

2026-06-11

·

Updated

2026-06-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ClipBucket v5 versions prior to 5.5.3 - #141
Description ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite all subtitle titles of any video they own in a single HTTP request.
Recommendations Update to version 5.5.3 - #141.

Exploit

Fix

Improper Neutralization of Wildcards

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49482

Affected Products

Clipbucket-V5