CVE-2026-100372

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web server user.

  • Published Sep 25, 2026
  • CVSS 8.6 high
  • 1.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-100372 at the National Vulnerability Database