Vulnerabilities > Uncannyowl > Uncanny Automator > 3.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-03-12 | CVE-2024-13838 | Server-Side Request Forgery (SSRF) vulnerability in Uncannyowl Uncanny Automator The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.2 via the 'call_webhook' method of the Automator_Send_Webhook class This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. | 3.8 |
2024-07-22 | CVE-2024-37117 | Unspecified vulnerability in Uncannyowl Uncanny Automator Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Automator Pro allows Reflected XSS.This issue affects Uncanny Automator Pro: from n/a through 5.3. | 6.1 |
2024-01-05 | CVE-2023-52151 | Unspecified vulnerability in Uncannyowl Uncanny Automator Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin.This issue affects Uncanny Automator – Automate everything with the #1 no-code automation and integration plugin: from n/a through 5.1.0.2. | 5.3 |