Easy!appointments
This hub aggregates every CVE we track for Easy!appointments, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
39
CVEs tracked
12
Critical
11
High
0
In CISA KEV
Severity distribution
CRITICAL12HIGH11MEDIUM11LOW5
Monthly trend
0
0
0
0
0
2
0
1
1
0
0
1
0
0
0
0
1
0
0
0
0
0
5
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Easy!appointments.
- CVE-2026-55651Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure7.1
- CVE-2026-52841Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync3.1
- CVE-2026-52840Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network2.7
- CVE-2026-52839Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass3.3
- CVE-2026-52838Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS2.6
- CVE-2026-23622CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover8.8
- CVE-2025-50383alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.8.1
- CVE-2025-29448Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking av...7.5
- CVE-2025-31828WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability4.3
- CVE-2024-57601Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.6.1
- CVE-2024-57602An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.9.8
- CVE-2023-3288A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.08.5
- CVE-2023-38055A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.09.6
- CVE-2023-38054A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.09.9
- CVE-2023-38053A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.09.9
Product normalization is registry-driven with AI assist and human review. How it works