Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

uncannyowl — Vulnerabilities & Security Advisories 9

Browse all 9 CVE security advisories affecting uncannyowl. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Uncannyowl primarily focuses on identifying vulnerabilities in web applications and enterprise software, with six CVEs recorded to date. Historically, their findings commonly involve remote code execution, cross-site scripting, and privilege escalation flaws, often in widely-used platforms. Their research has highlighted critical issues in content management systems and authentication mechanisms, though no major public security incidents have been directly attributed to their disclosures. The researcher maintains a reputation for thorough vulnerability analysis and responsible reporting practices, typically working with vendors to remediate issues before public disclosure. Their contributions have consistently improved security postures across multiple software ecosystems.

Found 8 results / 9 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-15025 Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin CWE-862 7.5 High 2026-07-28
CVE-2026-15008 Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin CWE-502 8.1 High 2026-07-16
CVE-2026-2269 Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin CWE-434 7.2 High 2026-03-03
CVE-2025-15522 Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin CWE-79 6.4 Medium 2026-01-23
CVE-2025-4520 Uncanny Automator <= 6.4.0.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin CWE-862 5.4 Medium 2025-05-14
CVE-2025-3623 Uncanny Automator <= 6.4.0.1 - Unauthenticated PHP Object Injection in automator_api_decode_message Function — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin CWE-502 9.1 Critical 2025-05-14
CVE-2025-2075 Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin CWE-862 8.8 High 2025-04-04
CVE-2024-13838 Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook — Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin CWE-918 5.5 Medium 2025-03-12

This page lists every published CVE security advisory associated with uncannyowl. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.