CVE-2013-10040: Clip-Bucket Clipbucket
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.
Affected products
- Clip-Bucket Clipbucket: up to and including 2.6
Published 2025-07-31. Last modified 2026-06-16.