« Volver al listado

Easyappointments

Easyappointments Easy Appointments: vulnerabilidades y CVE

Easyappointments Easy Appointments tiene 23 vulnerabilidades publicadas, 23 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE23
Últimos 12 meses23
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-9232Media (6.5)0.47%—19 sept 2026
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers,…
CVE-2026-87966Media (5.3)0.30%—18 sept 2026
The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a…
CVE-2026-87965Media (4.8)0.27%—18 sept 2026
The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded…
CVE-2026-81798Alta (7.1)0.25%—8 sept 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.
CVE-2026-19406Baja (2.7)0.32%—19 ago 2026
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read…
CVE-2026-14225Baja (2.7)0.32%—6 ago 2026
The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while…
CVE-2026-14226Media (4.3)0.29%—30 jul 2026
The Easy Appointments WordPress plugin before 3.12.28 does not require a sufficient capability on one of its appointment-listing REST endpoints, restricting it only to a capability that every authenticated user holds,…
CVE-2026-14223Media (4.3)0.27%—30 jul 2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify ownership or capability when returning stored customer details, allowing users with subscriber-level access to read any customer's personal…
CVE-2026-14222Baja (3.8)0.32%—30 jul 2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking…
CVE-2026-14221Baja (3.8)0.26%—30 jul 2026
The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with…
CVE-2026-14188Baja (2.7)0.32%—30 jul 2026
The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read…
CVE-2026-14224Media (5.4)0.23%—29 jul 2026
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the current user; the action only checks a shared nonce that any…
CVE-2026-8789Alta (8.1)0.40%—24 jul 2026
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all…
CVE-2026-61946Media (6.5)0.33%—23 jul 2026
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
CVE-2026-52841Baja (3.1)0.21%—14 jul 2026
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/controllers/Google.php:278` stores its URL-supplied `provider_id` in the session, and…
CVE-2026-52840Baja (2.7)0.31%—14 jul 2026
Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `application/controllers/Caldav.php:60` hands the request's `caldav_url` to a Guzzle `REPORT` call…
CVE-2026-52839Baja (3.3)0.23%—14 jul 2026
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an intended…
CVE-2026-52838Baja (2.6)0.24%—14 jul 2026
Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. That value is stored in the…
CVE-2026-52837Media (6.9)0.56%—14 jul 2026
Easy!Appointments is a self hosted appointment scheduler. In versions up to and including 1.5.2, the booking reschedule view at `/index.php/booking/reschedule/{appointment_hash}` (handled by `Booking::index()`) embeds…
CVE-2026-11992Media (4.3)0.46%—10 jul 2026
The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an…
CVE-2026-39513Alta (7.5)0.39%—15 jun 2026
Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
CVE-2026-2262Alta (7.5)2.4%—18 abr 2026
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due…
CVE-2025-49398Media (6.5)0.24%—6 nov 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1005 Data from Local System2
  3. T1078 Valid Accounts2
  4. T1210 Exploitation of Remote Services2
  5. T1059.007 JavaScript1
  6. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Easyappointments