CVE-2026-49482

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite all subtitle titles of any video they own in a single HTTP request. This issue has been patched in version 5.5.3 - #141.
Configurations

No configuration.

History

12 Jun 2026, 15:16

Type Values Removed Values Added
References () https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-wv43-277p-737c - () https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-wv43-277p-737c -

12 Jun 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 00:16

Updated : 2026-06-17 10:55


NVD link : CVE-2026-49482

Mitre link : CVE-2026-49482

CVE.ORG link : CVE-2026-49482


JSON object : View

Products Affected

No product.

CWE
CWE-155

Improper Neutralization of Wildcards or Matching Symbols

CWE-943

Improper Neutralization of Special Elements in Data Query Logic