---
cve: "CVE-2025-64336"
severity: "HIGH"
cvss: 7.2
epss: "0.3%"
vendor: "MacWarrior"
kev: false
exploited: false
published: "2025-11-07 05:16:08"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-27T01:27:58+02:00"
---

# CVE-2025-64336

> 7.2 HIGH · 🧪 PoC

## Beschreibung

ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is vulnerable to stored Cross-site Scripting (XSS). An authenticated regular user can upload a photo with a malicious Photo Title containing HTML/JavaScript code. While the payload does not execute in the user-facing photo gallery or detail pages, it is rendered unsafely in the Admin → Manage Photos section, resulting in JavaScript execution in the administrator’s browser. This issue is fixed in version 5.5.2-#147.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |

## Patch verfügbar (OSV)

- 97b02b8cb780abb1fe21a6c1b1fa39238a559a19 (Commit)
- 8e3cf79ce2721fbebde68a05a9a1a6319f086bcc (Commit)

## Referenzen

- <https://github.com/MacWarrior/clipbucket-v5/security/advisories/GHSA-hjc2-5329-j49w>
- <https://github.com/MacWarrior/clipbucket-v5/commit/8e3cf79ce2721fbebde68a05a9a1a6319f086bcc>
- <https://github.com/MacWarrior/clipbucket-v5/releases/tag/5.5.2-%23147>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-64336) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
