An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/MacWarrior/clipbucket-v5/blob/5.5.0/upload/actions/photo_uploader.php | Patch | 
| https://github.com/MacWarrior/clipbucket-v5/releases?page=2 | Release Notes | 
| https://github.com/MacWarrior/clipbucket-v5/tree/5.5.0 | Patch Mitigation | 
| https://medium.com/@mukund.s1337/cve-2025-55912-clipbucket-5-5-0-unauthenticated-arbitrary-file-upload-rce-720c0c0fbc58 | Exploit Third Party Advisory | 
Configurations
                    History
                    25 Sep 2025, 15:51
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/MacWarrior/clipbucket-v5/blob/5.5.0/upload/actions/photo_uploader.php - Patch | |
| References | () https://github.com/MacWarrior/clipbucket-v5/releases?page=2 - Release Notes | |
| References | () https://github.com/MacWarrior/clipbucket-v5/tree/5.5.0 - Patch, Mitigation | |
| References | () https://medium.com/@mukund.s1337/cve-2025-55912-clipbucket-5-5-0-unauthenticated-arbitrary-file-upload-rce-720c0c0fbc58 - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:oxygenz:clipbucket_v5:*:*:*:*:*:*:*:* | |
| First Time | Oxygenz Oxygenz clipbucket V5 | 
18 Sep 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.3 | 
| CWE | CWE-434 | 
18 Sep 2025, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-09-18 16:15
Updated : 2025-09-25 15:51
NVD link : CVE-2025-55912
Mitre link : CVE-2025-55912
CVE.ORG link : CVE-2025-55912
JSON object : View
Products Affected
                oxygenz
- clipbucket_v5
CWE
                
                    
                        
                        CWE-434
                        
            Unrestricted Upload of File with Dangerous Type
