Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.47%—Easyappointments Easy AppointmentsAI19/9/202621/9/2026
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers…
AplazadaMedia (5.3)0.30%—Easyappointments Easy AppointmentsAI18/9/202618/9/2026
The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on…
AplazadaMedia (4.8)0.27%—Easyappointments Easy AppointmentsAI18/9/202618/9/2026
The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that…
AplazadaAlta (7.1)0.25%—Easyappointments Easy AppointmentsAI8/9/20268/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI19/8/202626/8/2026
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI6/8/202626/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary…
AplazadaMedia (4.3)0.29%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer…
AplazadaMedia (4.3)0.27%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
AplazadaBaja (3.8)0.32%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
AplazadaBaja (3.8)0.26%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and…
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
AplazadaMedia (5.4)0.23%—Easyappointments Easy AppointmentsAI29/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an…
AplazadaAlta (8.1)0.40%—Easyappointments Easy AppointmentsAI24/7/202624/7/2026
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.33%—Easyappointments Easy AppointmentsAI23/7/202623/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
AplazadaBaja (3.1)0.21%—Easyappointments Easy AppointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the…
AplazadaBaja (2.7)0.31%—Easyappointments Easy AppointmentsAI14/7/202615/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches…
AplazadaBaja (3.3)0.23%—Easyappointments Easy AppointmentsAI14/7/202629/7/2026
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints `appointments/store` and `appointments/update`…
AplazadaBaja (2.6)0.24%—Easyappointments Easy AppointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` setting via a rich-text editor and later passed directly to the public…
AplazadaMedia (6.9)0.56%—Easyappointments Easy AppointmentsAI14/7/202629/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer record as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`)…
AplazadaMedia (4.3)0.46%—Easyappointments Easy AppointmentsAI10/7/202610/7/2026
The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to…
AplazadaAlta (7.5)0.39%—Easyappointments Easy AppointmentsAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
AplazadaAlta (7.5)2.4%—Easyappointments Easy AppointmentsAI18/4/202617/6/2026
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due to the endpoint being registered with `'permission_callback' => '__return_true'`, which allows…
AnalizadaAlta (7.4)0.23%—Easyappointments Easy!appointments15/1/202617/6/2026
Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or…
AplazadaMedia (6.5)0.24%—Easyappointments Easy AppointmentsAI6/11/202517/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14.
ModificadaAlta (8.1)0.36%—Easyappointments Easy!appointments25/8/20255/7/2026
alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.