CVE-2025-64114
Last modified
CVE-2025-64114 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrators with plugin management privileges to execute arbitrary SQL commands against the database through its ClipBucket Custom Fields plugin. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrators with plugin management privileges to execute arbitrary SQL commands against the database through its ClipBucket Custom Fields plugin. The vulnerabilities require the Custom Fields plugin to be installed and accessible, and can only be exploited by users with administrative access to the plugin interface. This issue is fixed in version 5.5.2 - #.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oxygenz | Clipbucket | >= 5.3, < 5.5.2-152 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-64114?
How severe is CVE-2025-64114?
How do I fix CVE-2025-64114?
Are you affected by CVE-2025-64114?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
