Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MacWarrior — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting MacWarrior. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MacWarrior operates as a specialized security testing framework designed for macOS environments, primarily targeting the validation of application integrity and system hardening. Its core utility lies in automating the detection of weaknesses within native and third-party macOS software, making it a critical tool for developers and security auditors seeking to preemptively identify flaws before deployment. Historically, vulnerabilities associated with this platform have frequently involved remote code execution, cross-site scripting, and privilege escalation issues, often stemming from improper input validation or insufficient access controls within its own modules. While no single catastrophic incident has defined its public history, the accumulation of twenty-two recorded CVEs highlights persistent challenges in maintaining secure codebases for complex security utilities. These findings underscore the necessity for rigorous peer review and continuous integration security testing, as even defensive tools can become attack vectors if their own internal mechanisms are compromised.

Found 38 results / 38 Clear Filters
Top products by MacWarrior: clipbucket-v5
CVE ID Title CVSS Severity Published
CVE-2026-103766 ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter — clipbucket-v5 CWE-89 7.2 High 2026-10-01
CVE-2026-102570 ClipBucket v5 through 5.5.3-#197 SQL Injection via language_id Parameter — clipbucket-v5 CWE-89 5.5 Medium 2026-09-29
CVE-2026-102569 ClipBucket v5 through 5.5.3-#197 SQL Injection via videoid Parameter — clipbucket-v5 CWE-89 5.5 Medium 2026-09-29
CVE-2026-100372 ClipBucket v5 before 5.5.3-#197 Path Traversal via template_editor.php — clipbucket-v5 CWE-22 7.2 High 2026-09-25
CVE-2026-96272 ClipBucket v5 before 5.5.3-#182 SQL Injection via search_result.php — clipbucket-v5 CWE-89 7.5 High 2026-09-23
CVE-2026-95812 ClipBucket v5 before 5.5.3-#182 Reflected XSS via Query Parameters — clipbucket-v5 CWE-79 6.1 Medium 2026-09-22
CVE-2026-77929 ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint — clipbucket-v5 CWE-434 8.8 High 2026-09-18
CVE-2026-77928 ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint — clipbucket-v5 CWE-89 6.5 Medium 2026-09-18
CVE-2026-77927 ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint — clipbucket-v5 CWE-89 6.5 Medium 2026-09-18
CVE-2026-80138 ClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath Parameter — clipbucket-v5 CWE-78 9.8 Critical 2026-08-25
CVE-2026-49482 ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite — clipbucket-v5 CWE-155 4.3 Medium 2026-06-11
CVE-2026-47238 ClipBucket: IDOR in videos subtitle editor — clipbucket-v5 CWE-639 6.5 Medium 2026-06-11
CVE-2026-45060 ClipBucket: Blind SQL Injection in progress_video.php — clipbucket-v5 CWE-89 9.8 Critical 2026-06-11
CVE-2026-42846 ClipBucket: Remote Play URL Command Injection — clipbucket-v5 CWE-78 9.8 Critical 2026-06-11
CVE-2026-45418 ClipBucket: Blind SQL Injection in subtitle_edit.php — clipbucket-v5 CWE-89 8.8 High 2026-06-11
CVE-2026-42847 ClipBucket: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') — clipbucket-v5 CWE-89 - - 2026-05-14
CVE-2026-32321 ClipBucket v5 has time-based Blind SQL Injection in ajax.php that leads to Data Exfiltration — clipbucket-v5 CWE-89 8.8 High 2026-03-18
CVE-2026-28354 ClipBucket v5 has IDOR in Collection Item Management — clipbucket-v5 CWE-639 4.3 - 2026-02-27
CVE-2026-26997 ClipBucket v5 has Stored XSS via Collection name — clipbucket-v5 CWE-79 5.4 - 2026-02-27
CVE-2026-26005 ClipBucket v5 enables internal network scans via an SSRF vulnerability — clipbucket-v5 CWE-918 5.0 Medium 2026-02-12
CVE-2026-25728 ClipBucket v5 Affected by Remote Code Execution via Avatar/Background File Upload Race Condition — clipbucket-v5 CWE-367 8.1AI High AI 2026-02-10
CVE-2026-21875 ClipBucket v5 Vulnerable to Blind SQL Injection through Channel Comments — clipbucket-v5 CWE-89 9.8 Critical 2026-01-07
CVE-2025-64338 ClipBucket's Manage Photos Feature is Vulnerable to Stored XSS via Collection Name — clipbucket-v5 CWE-79 - - 2025-12-15
CVE-2025-65113 ClipBucket v5 Unauthenticated Object Flagging Vulnerability — clipbucket-v5 CWE-770 6.5 Medium 2025-11-29
CVE-2025-62709 ClipBucket v5 is vulnerable to password reset link manipulation — clipbucket-v5 CWE-640 6.8 Medium 2025-11-20
CVE-2025-64339 ClipBucket v5: Stored XSS Vulnerability in Manage Playlists — clipbucket-v5 CWE-79 5.4 - 2025-11-07
CVE-2025-64336 ClipBucket v5's Manage Photo Feature is Vulnerable to Stored XSS Attack via Photo Title — clipbucket-v5 CWE-79 5.4 - 2025-11-07
CVE-2025-64114 ClipBucket v5: SQL Injection possible through ClipBucket Custom Fields plugin — clipbucket-v5 CWE-89 6.5 Medium 2025-11-05
CVE-2025-62715 ClipBucket v5: Stored XSS via Collection Tags — clipbucket-v5 CWE-79 5.4AI Medium AI 2025-11-04
CVE-2025-62429 ClipBucket v5 executes arbitrary PHP code — clipbucket-v5 CWE-94 7.2 High 2025-10-20

This page lists every published CVE security advisory associated with MacWarrior. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.