CVE-2025-55912: Oxygenz Clipbucket

High severity, CVSS 7.3. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler

Affected products

  • Oxygenz Clipbucket: up to and including 5.5.0

Published 2025-09-18. Last modified 2026-06-17.