Easyappointments
Easyappointments: vulnerabilidades y CVE
Easyappointments tiene 27 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses2
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-50455 | Crítica (9.1) | 1.2% | — | 27 jul 2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by… |
| CVE-2026-55651 | Alta (7.1) | 0.32% | — | 14 jul 2026 | Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging… |
| CVE-2024-57602 | Crítica (9.8) | 0.83% | — | 12 feb 2025 | An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file. |
| CVE-2024-57601 | Media (6.1) | 0.52% | — | 12 feb 2025 | Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter. |
| CVE-2023-3290 | Media (5) | 0.29% | — | 9 jul 2024 | A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation. |
| CVE-2023-3289 | Media (6.5) | 0.33% | — | 9 jul 2024 | A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation. |
| CVE-2023-3288 | Alta (8.8) | 0.35% | — | 9 jul 2024 | A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation. |
| CVE-2023-3287 | Alta (8.8) | 0.43% | — | 9 jul 2024 | A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation. |
| CVE-2023-3286 | Media (6.5) | 0.33% | — | 9 jul 2024 | A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation. |
| CVE-2023-38055 | Alta (8.1) | 0.39% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized… |
| CVE-2023-38054 | Alta (8.1) | 0.40% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data… |
| CVE-2023-38053 | Alta (8.1) | 0.40% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized… |
| CVE-2023-38052 | Alta (8.1) | 0.40% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation. |
| CVE-2023-38051 | Alta (8.1) | 0.40% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data… |
| CVE-2023-38050 | Alta (8.1) | 0.36% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data… |
| CVE-2023-38049 | Alta (8.1) | 0.41% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and… |
| CVE-2023-38048 | Alta (8.1) | 0.40% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data… |
| CVE-2023-38047 | Alta (8.1) | 0.37% | — | 9 jul 2024 | A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized… |
| CVE-2023-3700 | Media (4.3) | 0.44% | — | 17 jul 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-2105 | Alta (8.8) | 0.67% | — | 15 abr 2023 | Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-2104 | Media (5.4) | 0.45% | — | 15 abr 2023 | Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-2103 | Media (5.4) | 0.47% | — | 15 abr 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-2102 | Media (4.8) | 0.50% | — | 15 abr 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-1367 | Baja (3.8) | 0.43% | — | 13 mar 2023 | Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2023-1269 | Crítica (9.8) | 0.74% | — | 8 mar 2023 | Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0. |
| CVE-2022-1397 | Alta (8.8) | 1.2% | — | 10 may 2022 | API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover. |
| CVE-2022-0482 | Crítica (9.1) | 44% | — | 9 mar 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. |