CVE-2025-55912

Publication date

2025-09-18 00:00:00

Family

mitre

State

PUBLISHED

Description

An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler