Vulnerability Details CVE-2025-55912
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
Exploit prediction scoring system (EPSS) score
EPSS Score 0.066
EPSS Ranking 90.7%
CVSS Severity
CVSS v3 Score 7.3
Products affected by CVE-2025-55912
-
cpe:2.3:a:oxygenz:clipbucket:2.0
-
cpe:2.3:a:oxygenz:clipbucket:5.3
-
cpe:2.3:a:oxygenz:clipbucket:5.3.1
-
cpe:2.3:a:oxygenz:clipbucket:5.4.0
-
cpe:2.3:a:oxygenz:clipbucket:5.4.1
-
cpe:2.3:a:oxygenz:clipbucket:5.5.0