Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

59 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.47%—Easyappointments Easy AppointmentsAI19/9/202621/9/2026
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers…
AplazadaMedia (5.3)0.30%—Easyappointments Easy AppointmentsAI18/9/202618/9/2026
The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on…
AplazadaMedia (4.8)0.27%—Easyappointments Easy AppointmentsAI18/9/202618/9/2026
The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that…
AplazadaAlta (7.1)0.25%—Easyappointments Easy AppointmentsAI8/9/20268/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI19/8/202626/8/2026
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI6/8/202626/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary…
AplazadaMedia (4.3)0.29%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds, allowing users with subscriber-level access to read all bookings on the site, including customer…
AplazadaMedia (4.3)0.27%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal information by iterating an identifier.
AplazadaBaja (3.8)0.32%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.
AplazadaBaja (3.8)0.26%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and…
AplazadaBaja (2.7)0.32%—Easyappointments Easy AppointmentsAI30/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
AplazadaMedia (5.4)0.23%—Easyappointments Easy AppointmentsAI29/7/202610/8/2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any authenticated user can obtain from their own appointment's edit form. A subscriber-level user with an…
AplazadaCrítica (9.1)1.2%—EasyappointmentsAICodeigniterAI27/7/202630/7/2026
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema…
AplazadaAlta (8.1)0.40%—Easyappointments Easy AppointmentsAI24/7/202624/7/2026
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.5)0.33%—Easyappointments Easy AppointmentsAI23/7/202623/7/2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
AplazadaAlta (7.1)0.32%—EasyappointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers,…
AplazadaBaja (3.1)0.21%—Easyappointments Easy AppointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and `oauth_callback` saves the issued Google OAuth token against that row without checking the caller owns the…
AplazadaBaja (2.7)0.31%—Easyappointments Easy AppointmentsAI14/7/202615/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call without scheme or host validation. A logged-in backend user (admin, provider, or secretary) reaches…
AplazadaBaja (3.3)0.23%—Easyappointments Easy AppointmentsAI14/7/202629/7/2026
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended security boundary. However, the direct mutation endpoints `appointments/store` and `appointments/update`…
AplazadaBaja (2.6)0.24%—Easyappointments Easy AppointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the `disable_booking_message` setting via a rich-text editor and later passed directly to the public…
AplazadaMedia (6.9)0.56%—Easyappointments Easy AppointmentsAI14/7/202629/7/2026
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds the entire customer record as inline JavaScript (`const vars = {... "customer_data": {...}, ...}`)…
AplazadaMedia (4.3)0.46%—Easyappointments Easy AppointmentsAI10/7/202610/7/2026
The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to…
AplazadaAlta (7.5)0.39%—Easyappointments Easy AppointmentsAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
AplazadaAlta (7.5)2.4%—Easyappointments Easy AppointmentsAI18/4/202617/6/2026
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due to the endpoint being registered with `'permission_callback' => '__return_true'`, which allows…
AnalizadaAlta (7.4)0.23%—Easyappointments Easy!appointments15/1/202617/6/2026
Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or…