An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php to upload arbitrary files without any authentication, due to missing access controls in the upload handler
{ "versions": [ { "introduced": "0" }, { "last_affected": "5.5.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55912.json"