Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.47% | — | Easyappointments Easy AppointmentsAI | 19/9/2026 | 21/9/2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers… | |
| Aplazada | Media (5.3) | 0.30% | — | Easyappointments Easy AppointmentsAI | 18/9/2026 | 18/9/2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on… | |
| Aplazada | Media (4.8) | 0.27% | — | Easyappointments Easy AppointmentsAI | 18/9/2026 | 18/9/2026 | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that… | |
| Aplazada | Alta (7.1) | 0.25% | — | Easyappointments Easy AppointmentsAI | 8/9/2026 | 8/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1. | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 19/8/2026 | 26/8/2026 | The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses. | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 6/8/2026 | 26/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary… | |
| Aplazada | Media (4.3) | 0.29% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer… | |
| Aplazada | Media (4.3) | 0.27% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier. | |
| Aplazada | Baja (3.8) | 0.32% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system. | |
| Aplazada | Baja (3.8) | 0.26% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and… | |
| Aplazada | Baja (2.7) | 0.32% | — | Easyappointments Easy AppointmentsAI | 30/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information. | |
| Aplazada | Media (5.4) | 0.23% | — | Easyappointments Easy AppointmentsAI | 29/7/2026 | 10/8/2026 | The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an… | |
| Aplazada | Alta (8.1) | 0.40% | — | Easyappointments Easy AppointmentsAI | 24/7/2026 | 24/7/2026 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.33% | — | Easyappointments Easy AppointmentsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions. | |
| Aplazada | Baja (3.1) | 0.21% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 14/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the… | |
| Aplazada | Baja (2.7) | 0.31% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 15/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches… | |
| Aplazada | Baja (3.3) | 0.23% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 29/7/2026 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints `appointments/store` and `appointments/update`… | |
| Aplazada | Baja (2.6) | 0.24% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 14/7/2026 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` setting via a rich-text editor and later passed directly to the public… | |
| Aplazada | Media (6.9) | 0.56% | — | Easyappointments Easy AppointmentsAI | 14/7/2026 | 29/7/2026 | Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer record as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`)… | |
| Aplazada | Media (4.3) | 0.46% | — | Easyappointments Easy AppointmentsAI | 10/7/2026 | 10/7/2026 | The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to… | |
| Aplazada | Alta (7.5) | 0.39% | — | Easyappointments Easy AppointmentsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions. | |
| Aplazada | Alta (7.5) | 2.4% | — | Easyappointments Easy AppointmentsAI | 18/4/2026 | 17/6/2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due to the endpoint being registered with `'permission_callback' => '__return_true'`, which allows… | |
| Analizada | Alta (7.4) | 0.23% | — | Easyappointments Easy!appointments | 15/1/2026 | 17/6/2026 | Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or… | |
| Aplazada | Media (6.5) | 0.24% | — | Easyappointments Easy AppointmentsAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14. | |
| Modificada | Alta (8.1) | 0.36% | — | Easyappointments Easy!appointments | 25/8/2025 | 5/7/2026 | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter. |