CVE-2013-10040: Clip-Bucket Clipbucket

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.

Affected products

Published 2025-07-31. Last modified 2026-06-16.