CVE-2026-100372 – ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php

​CVE ID :CVE-2026-100372

Published : Sept. 25, 2026, 8:17 p.m. | 1 hour, 12 minutes ago

Description :ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web server user.

Severity: 8.6 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More