easyappointments records
34 published records for vendor easyappointments.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 58.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-639 Authorization Bypass Through User-Controlled Key15
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-269 Improper Privilege Management2
- CWE-284 Improper Access Control2
- CWE-862 Missing Authorization2
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2022-0482Proof of concept | Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-359 | Critical9.1 | — | 43.7% | Mar 9, 2022 |
39Monitor | CVE-2024-57602No exploit | An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.easyappointments · easyappointments · CWE-269 | Critical9.8 | — | 0.8% | Feb 12, 2025 |
39Monitor | CVE-2023-1269No exploit | Use of Hard-coded Credentials in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-798 | Critical9.8 | — | 0.7% | Mar 8, 2023 |
35Monitor | CVE-2022-1397No exploit | API Privilege Escalation in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-269 | High8.8 | — | 1.2% | May 10, 2022 |
35Monitor | CVE-2023-2105No exploit | Session Fixation in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-384 | High8.8 | — | 0.7% | Apr 15, 2023 |
35Monitor | CVE-2023-3287No exploit | A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.8 | — | 0.4% | Jul 9, 2024 |
35Monitor | CVE-2023-3288No exploit | A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.8 | — | 0.3% | Jul 9, 2024 |
35Monitor | CVE-2025-31828No exploit | WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerabilityeasyappointments · easy\!appointments · CWE-352 | High8.8 | — | 0.2% | Apr 1, 2025 |
32Monitor | CVE-2023-38049No exploit | A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
32Monitor | CVE-2023-38052No exploit | A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
32Monitor | CVE-2023-38048No exploit | A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
32Monitor | CVE-2023-38053No exploit | A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
32Monitor | CVE-2023-38051No exploit | A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
32Monitor | CVE-2023-38054No exploit | A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
32Monitor | CVE-2023-38055No exploit | A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
32Monitor | CVE-2023-38047No exploit | A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0.easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
32Monitor | CVE-2025-50383Proof of concept | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.easyappointments · easy\!appointments · CWE-89 | High8.1 | — | 0.4% | Aug 25, 2025 |
32Monitor | CVE-2023-38050No exploit | A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | High8.1 | — | 0.4% | Jul 9, 2024 |
30Monitor | CVE-2018-13063No exploit | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.easyappointments · easy\!appointments · CWE-862 | High7.5 | — | 1.3% | Mar 16, 2020 |
30Monitor | CVE-2025-29448Proof of concept | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causeasyappointments · easy\!appointments · CWE-284 | High7.5 | — | 0.6% | May 7, 2025 |
29Monitor | CVE-2026-23622No exploit | CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeovereasyappointments · easy\!appointments · CWE-352 | High7.4 | — | 0.2% | Jan 15, 2026 |
26Monitor | CVE-2018-13060No exploit | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.easyappointments · easy\!appointments · CWE-287 | Medium6.5 | — | 0.9% | Mar 16, 2020 |
26Monitor | CVE-2023-3289No exploit | A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Medium6.5 | — | 0.3% | Jul 9, 2024 |
26Monitor | CVE-2023-3286No exploit | A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Medium6.5 | — | 0.3% | Jul 9, 2024 |
25Monitor | CVE-2023-32295No exploit | WordPress Easy!Appointments plugin <= 1.3.3 - Arbitrary File Deletion vulnerabilityeasyappointments · easy\!appointments · CWE-862 | Medium6.3 | — | 0.5% | Apr 11, 2024 |
- CVE-2022-048249Plan
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
CriticalCVSS 9.1Proof of conceptEPSS 44%easyappointments · easyappointmentsMar 9, 2022
- CVE-2024-5760239Monitor
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
CriticalCVSS 9.8No exploitEPSS 1%easyappointments · easyappointmentsFeb 12, 2025
- CVE-2023-126939Monitor
Use of Hard-coded Credentials in alextselegidis/easyappointments
CriticalCVSS 9.8No exploitEPSS 1%easyappointments · easyappointmentsMar 8, 2023
- CVE-2022-139735Monitor
API Privilege Escalation in alextselegidis/easyappointments
HighCVSS 8.8No exploitEPSS 1%easyappointments · easyappointmentsMay 10, 2022
- CVE-2023-210535Monitor
Session Fixation in alextselegidis/easyappointments
HighCVSS 8.8No exploitEPSS 1%easyappointments · easyappointmentsApr 15, 2023
- CVE-2023-328735Monitor
A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0
HighCVSS 8.8No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-328835Monitor
A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.0
HighCVSS 8.8No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2025-3182835Monitor
WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
HighCVSS 8.8No exploitEPSS 0%easyappointments · easy\!appointmentsApr 1, 2025
- CVE-2023-3804932Monitor
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} in EasyAppointments < 1.5.0
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-3805232Monitor
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-3804832Monitor
A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} in EasyAppointments < 1.5.0
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-3805332Monitor
A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.0
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-3805132Monitor
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-3805432Monitor
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.0
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-3805532Monitor
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.0
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-3804732Monitor
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0.
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2025-5038332Monitor
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
HighCVSS 8.1Proof of conceptEPSS 0%easyappointments · easy\!appointmentsAug 25, 2025
- CVE-2023-3805032Monitor
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} in EasyAppointments < 1.5.0
HighCVSS 8.1No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2018-1306330Monitor
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
HighCVSS 7.5No exploitEPSS 1%easyappointments · easy\!appointmentsMar 16, 2020
- CVE-2025-2944830Monitor
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, caus
HighCVSS 7.5Proof of conceptEPSS 1%easyappointments · easy\!appointmentsMay 7, 2025
- CVE-2026-2362229Monitor
CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover
HighCVSS 7.4No exploitEPSS 0%easyappointments · easy\!appointmentsJan 15, 2026
- CVE-2018-1306026Monitor
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
MediumCVSS 6.5No exploitEPSS 1%easyappointments · easy\!appointmentsMar 16, 2020
- CVE-2023-328926Monitor
A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0
MediumCVSS 6.5No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-328626Monitor
A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0
MediumCVSS 6.5No exploitEPSS 0%easyappointments · easyappointmentsJul 9, 2024
- CVE-2023-3229525Monitor
WordPress Easy!Appointments plugin <= 1.3.3 - Arbitrary File Deletion vulnerability
MediumCVSS 6.3No exploitEPSS 1%easyappointments · easy\!appointmentsApr 11, 2024