easyappointments kayıtları
easyappointments üreticisine ait 34 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %58,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-639 Authorization Bypass Through User-Controlled Key15
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-269 Improper Privilege Management2
- CWE-284 Improper Access Control2
- CWE-862 Missing Authorization2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
34 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2022-0482Kavram kanıtı | Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-359 | Kritik9,1 | — | %43,7 | 9 Mar 2022 |
39İzleyin | CVE-2024-57602İstismar yok | An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.easyappointments · easyappointments · CWE-269 | Kritik9,8 | — | %0,8 | 12 Şub 2025 |
39İzleyin | CVE-2023-1269İstismar yok | Use of Hard-coded Credentials in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-798 | Kritik9,8 | — | %0,7 | 8 Mar 2023 |
35İzleyin | CVE-2022-1397İstismar yok | API Privilege Escalation in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-269 | Yüksek8,8 | — | %1,2 | 10 May 2022 |
35İzleyin | CVE-2023-2105İstismar yok | Session Fixation in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-384 | Yüksek8,8 | — | %0,7 | 15 Nis 2023 |
35İzleyin | CVE-2023-3287İstismar yok | A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,8 | — | %0,4 | 9 Tem 2024 |
35İzleyin | CVE-2023-3288İstismar yok | A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,8 | — | %0,3 | 9 Tem 2024 |
35İzleyin | CVE-2025-31828İstismar yok | WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerabilityeasyappointments · easy\!appointments · CWE-352 | Yüksek8,8 | — | %0,2 | 1 Nis 2025 |
32İzleyin | CVE-2023-38049İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
32İzleyin | CVE-2023-38052İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
32İzleyin | CVE-2023-38048İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
32İzleyin | CVE-2023-38053İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
32İzleyin | CVE-2023-38051İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
32İzleyin | CVE-2023-38054İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
32İzleyin | CVE-2023-38055İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
32İzleyin | CVE-2023-38047İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0.easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
32İzleyin | CVE-2025-50383Kavram kanıtı | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.easyappointments · easy\!appointments · CWE-89 | Yüksek8,1 | — | %0,4 | 25 Ağu 2025 |
32İzleyin | CVE-2023-38050İstismar yok | A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Yüksek8,1 | — | %0,4 | 9 Tem 2024 |
30İzleyin | CVE-2018-13063İstismar yok | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.easyappointments · easy\!appointments · CWE-862 | Yüksek7,5 | — | %1,3 | 16 Mar 2020 |
30İzleyin | CVE-2025-29448Kavram kanıtı | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causeasyappointments · easy\!appointments · CWE-284 | Yüksek7,5 | — | %0,6 | 7 May 2025 |
29İzleyin | CVE-2026-23622İstismar yok | CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeovereasyappointments · easy\!appointments · CWE-352 | Yüksek7,4 | — | %0,2 | 15 Oca 2026 |
26İzleyin | CVE-2018-13060İstismar yok | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.easyappointments · easy\!appointments · CWE-287 | Orta6,5 | — | %0,9 | 16 Mar 2020 |
26İzleyin | CVE-2023-3289İstismar yok | A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Orta6,5 | — | %0,3 | 9 Tem 2024 |
26İzleyin | CVE-2023-3286İstismar yok | A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Orta6,5 | — | %0,3 | 9 Tem 2024 |
25İzleyin | CVE-2023-32295İstismar yok | WordPress Easy!Appointments plugin <= 1.3.3 - Arbitrary File Deletion vulnerabilityeasyappointments · easy\!appointments · CWE-862 | Orta6,3 | — | %0,5 | 11 Nis 2024 |
- CVE-2022-048249Planlayın
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
KritikCVSS 9,1Kavram kanıtıEPSS %44easyappointments · easyappointments9 Mar 2022
- CVE-2024-5760239İzleyin
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
KritikCVSS 9,8İstismar yokEPSS %1easyappointments · easyappointments12 Şub 2025
- CVE-2023-126939İzleyin
Use of Hard-coded Credentials in alextselegidis/easyappointments
KritikCVSS 9,8İstismar yokEPSS %1easyappointments · easyappointments8 Mar 2023
- CVE-2022-139735İzleyin
API Privilege Escalation in alextselegidis/easyappointments
YüksekCVSS 8,8İstismar yokEPSS %1easyappointments · easyappointments10 May 2022
- CVE-2023-210535İzleyin
Session Fixation in alextselegidis/easyappointments
YüksekCVSS 8,8İstismar yokEPSS %1easyappointments · easyappointments15 Nis 2023
- CVE-2023-328735İzleyin
A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0
YüksekCVSS 8,8İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-328835İzleyin
A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.0
YüksekCVSS 8,8İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2025-3182835İzleyin
WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0easyappointments · easy\!appointments1 Nis 2025
- CVE-2023-3804932İzleyin
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} in EasyAppointments < 1.5.0
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-3805232İzleyin
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-3804832İzleyin
A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} in EasyAppointments < 1.5.0
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-3805332İzleyin
A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.0
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-3805132İzleyin
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-3805432İzleyin
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.0
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-3805532İzleyin
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.0
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-3804732İzleyin
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0.
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2025-5038332İzleyin
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
YüksekCVSS 8,1Kavram kanıtıEPSS %0easyappointments · easy\!appointments25 Ağu 2025
- CVE-2023-3805032İzleyin
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} in EasyAppointments < 1.5.0
YüksekCVSS 8,1İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2018-1306330İzleyin
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
YüksekCVSS 7,5İstismar yokEPSS %1easyappointments · easy\!appointments16 Mar 2020
- CVE-2025-2944830İzleyin
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, caus
YüksekCVSS 7,5Kavram kanıtıEPSS %1easyappointments · easy\!appointments7 May 2025
- CVE-2026-2362229İzleyin
CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover
YüksekCVSS 7,4İstismar yokEPSS %0easyappointments · easy\!appointments15 Oca 2026
- CVE-2018-1306026İzleyin
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
OrtaCVSS 6,5İstismar yokEPSS %1easyappointments · easy\!appointments16 Mar 2020
- CVE-2023-328926İzleyin
A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0
OrtaCVSS 6,5İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-328626İzleyin
A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0
OrtaCVSS 6,5İstismar yokEPSS %0easyappointments · easyappointments9 Tem 2024
- CVE-2023-3229525İzleyin
WordPress Easy!Appointments plugin <= 1.3.3 - Arbitrary File Deletion vulnerability
OrtaCVSS 6,3İstismar yokEPSS %1easyappointments · easy\!appointments11 Nis 2024