CVE-2025-55912: Oxygenz Clipbucket
High severity, CVSS 7.3. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
Affected products
- Oxygenz Clipbucket: up to and including 5.5.0
Published 2025-09-18. Last modified 2026-06-17.