Записи easyappointments
34 опубликованных записей вендора easyappointments.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 58,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-639 Authorization Bypass Through User-Controlled Key15
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-269 Improper Privilege Management2
- CWE-284 Improper Access Control2
- CWE-862 Missing Authorization2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2022-0482Proof of concept | Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-359 | Критическая9,1 | — | 43,7 % | 9 мар. 2022 г. |
39Наблюдать | CVE-2024-57602Эксплойта нет | An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.easyappointments · easyappointments · CWE-269 | Критическая9,8 | — | 0,8 % | 12 февр. 2025 г. |
39Наблюдать | CVE-2023-1269Эксплойта нет | Use of Hard-coded Credentials in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-798 | Критическая9,8 | — | 0,7 % | 8 мар. 2023 г. |
35Наблюдать | CVE-2022-1397Эксплойта нет | API Privilege Escalation in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-269 | Высокая8,8 | — | 1,1 % | 10 мая 2022 г. |
35Наблюдать | CVE-2023-2105Эксплойта нет | Session Fixation in alextselegidis/easyappointmentseasyappointments · easyappointments · CWE-384 | Высокая8,8 | — | 0,7 % | 15 апр. 2023 г. |
35Наблюдать | CVE-2023-3287Эксплойта нет | A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,8 | — | 0,4 % | 9 июл. 2024 г. |
35Наблюдать | CVE-2023-3288Эксплойта нет | A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,8 | — | 0,3 % | 9 июл. 2024 г. |
35Наблюдать | CVE-2025-31828Эксплойта нет | WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerabilityeasyappointments · easy\!appointments · CWE-352 | Высокая8,8 | — | 0,2 % | 1 апр. 2025 г. |
32Наблюдать | CVE-2023-38049Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2023-38052Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2023-38048Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2023-38053Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2023-38051Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2023-38054Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2023-38055Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2023-38047Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0.easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
32Наблюдать | CVE-2025-50383Proof of concept | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.easyappointments · easy\!appointments · CWE-89 | Высокая8,1 | — | 0,4 % | 25 авг. 2025 г. |
32Наблюдать | CVE-2023-38050Эксплойта нет | A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Высокая8,1 | — | 0,4 % | 9 июл. 2024 г. |
30Наблюдать | CVE-2018-13063Эксплойта нет | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.easyappointments · easy\!appointments · CWE-862 | Высокая7,5 | — | 1,3 % | 16 мар. 2020 г. |
30Наблюдать | CVE-2025-29448Proof of concept | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causeasyappointments · easy\!appointments · CWE-284 | Высокая7,5 | — | 0,6 % | 7 мая 2025 г. |
29Наблюдать | CVE-2026-23622Эксплойта нет | CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeovereasyappointments · easy\!appointments · CWE-352 | Высокая7,4 | — | 0,2 % | 15 янв. 2026 г. |
26Наблюдать | CVE-2018-13060Эксплойта нет | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.easyappointments · easy\!appointments · CWE-287 | Средняя6,5 | — | 0,9 % | 16 мар. 2020 г. |
26Наблюдать | CVE-2023-3289Эксплойта нет | A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Средняя6,5 | — | 0,3 % | 9 июл. 2024 г. |
26Наблюдать | CVE-2023-3286Эксплойта нет | A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0easyappointments · easyappointments · CWE-639 | Средняя6,5 | — | 0,3 % | 9 июл. 2024 г. |
25Наблюдать | CVE-2023-32295Эксплойта нет | WordPress Easy!Appointments plugin <= 1.3.3 - Arbitrary File Deletion vulnerabilityeasyappointments · easy\!appointments · CWE-862 | Средняя6,3 | — | 0,5 % | 11 апр. 2024 г. |
- CVE-2022-048249В плане
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
КритическаяCVSS 9,1Proof of conceptEPSS 44 %easyappointments · easyappointments9 мар. 2022 г.
- CVE-2024-5760239Наблюдать
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %easyappointments · easyappointments12 февр. 2025 г.
- CVE-2023-126939Наблюдать
Use of Hard-coded Credentials in alextselegidis/easyappointments
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %easyappointments · easyappointments8 мар. 2023 г.
- CVE-2022-139735Наблюдать
API Privilege Escalation in alextselegidis/easyappointments
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %easyappointments · easyappointments10 мая 2022 г.
- CVE-2023-210535Наблюдать
Session Fixation in alextselegidis/easyappointments
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %easyappointments · easyappointments15 апр. 2023 г.
- CVE-2023-328735Наблюдать
A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-328835Наблюдать
A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.0
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2025-3182835Наблюдать
WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %easyappointments · easy\!appointments1 апр. 2025 г.
- CVE-2023-3804932Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} in EasyAppointments < 1.5.0
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-3805232Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-3804832Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} in EasyAppointments < 1.5.0
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-3805332Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.0
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-3805132Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-3805432Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.0
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-3805532Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.0
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-3804732Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2025-5038332Наблюдать
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
ВысокаяCVSS 8,1Proof of conceptEPSS 0 %easyappointments · easy\!appointments25 авг. 2025 г.
- CVE-2023-3805032Наблюдать
A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} in EasyAppointments < 1.5.0
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2018-1306330Наблюдать
Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %easyappointments · easy\!appointments16 мар. 2020 г.
- CVE-2025-2944830Наблюдать
Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, caus
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %easyappointments · easy\!appointments7 мая 2025 г.
- CVE-2026-2362229Наблюдать
CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %easyappointments · easy\!appointments15 янв. 2026 г.
- CVE-2018-1306026Наблюдать
Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %easyappointments · easy\!appointments16 мар. 2020 г.
- CVE-2023-328926Наблюдать
A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0
СредняяCVSS 6,5Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-328626Наблюдать
A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0
СредняяCVSS 6,5Эксплойта нетEPSS 0 %easyappointments · easyappointments9 июл. 2024 г.
- CVE-2023-3229525Наблюдать
WordPress Easy!Appointments plugin <= 1.3.3 - Arbitrary File Deletion vulnerability
СредняяCVSS 6,3Эксплойта нетEPSS 1 %easyappointments · easy\!appointments11 апр. 2024 г.