Easyappointments
Easyappointments Easy!appointments: vulnerabilidades y CVE
Easyappointments Easy!appointments tiene 9 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-23622 | Alta (7.4) | 0.23% | — | 15 ene 2026 | Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several… |
| CVE-2025-50383 | Alta (8.1) | 0.36% | — | 25 ago 2025 | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter. |
| CVE-2025-29448 | Alta (7.5) | 0.56% | — | 7 may 2025 | Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability. |
| CVE-2025-31828 | Alta (8.8) | 0.24% | — | 1 abr 2025 | Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2. |
| CVE-2023-32295 | Media (6.3) | 0.51% | — | 11 abr 2024 | Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3. |
| CVE-2024-0698 | Media (5.4) | 0.40% | — | 5 mar 2024 | The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization… |
| CVE-2018-13063 | Alta (7.5) | 1.3% | — | 16 mar 2020 | Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts. |
| CVE-2018-13060 | Media (6.5) | 0.92% | — | 16 mar 2020 | Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue. |
| CVE-2019-14936 | Media (5.3) | 1.5% | — | 11 sept 2019 | Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash). |