Skip to content
Noroxi

easyappointments records

34 published records for vendor easyappointments.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
58.8%
Median publish → KEV
No record has entered KEV

All records

34 records
  • Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments

    CriticalCVSS 9.1Proof of conceptEPSS 44%

    easyappointments · easyappointmentsMar 9, 2022

  • An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.

    CriticalCVSS 9.8No exploitEPSS 1%

    easyappointments · easyappointmentsFeb 12, 2025

  • CVE-2023-1269
    39Monitor

    Use of Hard-coded Credentials in alextselegidis/easyappointments

    CriticalCVSS 9.8No exploitEPSS 1%

    easyappointments · easyappointmentsMar 8, 2023

  • CVE-2022-1397
    35Monitor

    API Privilege Escalation in alextselegidis/easyappointments

    HighCVSS 8.8No exploitEPSS 1%

    easyappointments · easyappointmentsMay 10, 2022

  • CVE-2023-2105
    35Monitor

    Session Fixation in alextselegidis/easyappointments

    HighCVSS 8.8No exploitEPSS 1%

    easyappointments · easyappointmentsApr 15, 2023

  • CVE-2023-3287
    35Monitor

    A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0

    HighCVSS 8.8No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • CVE-2023-3288
    35Monitor

    A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.0

    HighCVSS 8.8No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    easyappointments · easy\!appointmentsApr 1, 2025

  • A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} in EasyAppointments < 1.5.0

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} in EasyAppointments < 1.5.0

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.0

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.0

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.0

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0.

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.

    HighCVSS 8.1Proof of conceptEPSS 0%

    easyappointments · easy\!appointmentsAug 25, 2025

  • A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} in EasyAppointments < 1.5.0

    HighCVSS 8.1No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.

    HighCVSS 7.5No exploitEPSS 1%

    easyappointments · easy\!appointmentsMar 16, 2020

  • Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, caus

    HighCVSS 7.5Proof of conceptEPSS 1%

    easyappointments · easy\!appointmentsMay 7, 2025

  • CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover

    HighCVSS 7.4No exploitEPSS 0%

    easyappointments · easy\!appointmentsJan 15, 2026

  • Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.

    MediumCVSS 6.5No exploitEPSS 1%

    easyappointments · easy\!appointmentsMar 16, 2020

  • CVE-2023-3289
    26Monitor

    A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0

    MediumCVSS 6.5No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • CVE-2023-3286
    26Monitor

    A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0

    MediumCVSS 6.5No exploitEPSS 0%

    easyappointments · easyappointmentsJul 9, 2024

  • WordPress Easy!Appointments plugin <= 1.3.3 - Arbitrary File Deletion vulnerability

    MediumCVSS 6.3No exploitEPSS 1%

    easyappointments · easy\!appointmentsApr 11, 2024