CRITICAL 9.2 NVD

CVE-2026-80138

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attacker

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary commands as the web server user.

References

Published: 2026-08-25 · Source: NVD · Feed updated: 2026-08-26
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-25 via NVD.

Risk Timeline

CVE Disclosed2026-08-25 · 0 days ago

Remediation Resources

vulnfeed aggregates 11369 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.