Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ClipBucket v5 through 5.5.3-#197 contains a time-based blind SQL injection vulnerability in the language update function where the language_id parameter is concatenated unescaped into the WHERE clause of an UPDATE statement. An authenticated administrator with basic_settings permission can inject arbitrary SQL payloads to extract or modify database contents. | |
| Title | ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter | |
| First Time appeared |
Clip-bucket
Clip-bucket clipbucket |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:clip-bucket:clipbucket:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Clip-bucket
Clip-bucket clipbucket |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-29T14:46:06.243Z
Reserved: 2026-09-29T13:43:16.047Z
Link: CVE-2026-102570
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')