Description
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws, allowing a normal authenticated user to modify another user’s collection items. This affects both add item (/actions/add_to_collection.php) due to missing authorization checks and delete item (/manage_collections.php?mode=manage_items...) due to a broken ownership check in removeItemFromCollection(). As a result, attackers can insert and remove items from collections they do not own. Version 5.5.3 #59 fixes the issue.
INFO
Published Date :
2026-02-27T19:18:25.500Z
Last Modified :
2026-02-27T20:23:22.876Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-28354 vulnerability.
| Vendors | Products |
|---|---|
| Macwarrior |
|
| Oxygenz |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-28354.