Skip to main content

Vendor/product archive

easyappointments / easy!appointments CVEs

Beta · best-effort

9 CVEs tagged to easyappointments / easy!appointments0 Critical, 4 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-23622

Published Jan 15, 2026

Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns ea…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-29448

Published May 7, 2025

Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31828

Published Apr 1, 2025

Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32295

Published Apr 11, 2024

Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0698

Published Mar 5, 2024

The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 d…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1