alextselegidis/easyappointments Security Advisories (20)
-
[LOW] Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
PKSA-qjn8-scvh-tqz1 CVE-2026-52838 GHSA-996f-334j-67g7
Affected version: <=1.5.2
Reported by:
GitHub -
[LOW] Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
PKSA-4qd5-bb9g-9x8d CVE-2026-52841 GHSA-8hm4-r66f-29wr
Affected version: <=1.5.2
Reported by:
GitHub -
[MEDIUM] Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
PKSA-nm1q-gc5c-m98k CVE-2026-52837 GHSA-xgr6-pqjv-3pf8
Affected version: <=1.5.2
Reported by:
GitHub -
[LOW] Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
PKSA-9k3m-y8wr-wv52 CVE-2026-52839 GHSA-w8xc-8g92-v77h
Affected version: <=1.5.2
Reported by:
GitHub -
[LOW] Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
PKSA-qvhv-yhm7-8xkk CVE-2026-52840 GHSA-pm5p-7w5h-jm5q
Affected version: <=1.5.2
Reported by:
GitHub -
[HIGH] Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
PKSA-hmm5-v3nr-ydfq CVE-2026-55651 GHSA-4vmm-5qvc-w5p7
Affected version: =1.5.2
Reported by:
GitHub -
[HIGH] alextselegidis/easyappointments is Vulnerable to CSRF Protection Bypass
PKSA-wm96-drjh-4138 CVE-2026-23622 GHSA-54v4-4685-vwrj
Affected version: <=1.5.2
Reported by:
GitHub -
[MEDIUM] Easy!Appointments SQL injection vulnerability
PKSA-ftwr-h2by-25z6 CVE-2025-50383 GHSA-2f28-69j7-85hf
Affected version: <1.5.2-beta.1
Reported by:
GitHub -
[MEDIUM] Easy!Appointments Denial of Service (DoS)
PKSA-w556-svhf-8jpc CVE-2025-29448 GHSA-hcjv-982c-5f29
Affected version: <=1.5.1
Reported by:
GitHub -
[CRITICAL] Easy!Appointments Improper Restriction of Excessive Authentication Attempts
PKSA-vj3c-qdk9-qkyt CVE-2024-57602 GHSA-8fc2-fhh6-f6m5
Affected version: <=1.5.0
Reported by:
GitHub -
[MEDIUM] Remote code execution in alextselegidis/easyappointments
PKSA-w16x-vhyz-f1p6 CVE-2024-57601 GHSA-3wf7-83q3-948c
Affected version: <=1.5.0
Reported by:
GitHub -
[MEDIUM] Easy!Appointments Improper Access Control vulnerability
PKSA-twkv-h3r3-vv25 CVE-2023-3700 GHSA-8c6q-26w6-qwhg
Affected version: <=1.4.3
Reported by:
GitHub -
[MEDIUM] alextselegidis/easyappointments vulnerable to Stored Cross-site Scripting
PKSA-7mfz-wxbh-wyvy CVE-2023-2102 GHSA-j6qq-9939-9jv8
Affected version: <=1.4.3
Reported by:
GitHub -
[MEDIUM] alextselegidis/easyappointments Session Fixation vulnerability
PKSA-pr9p-tp6q-k96z CVE-2023-2105 GHSA-4qmm-cv4r-qfr4
Affected version: <=1.4.3
Reported by:
GitHub -
[MEDIUM] alextselegidis/easyappointments Improper Access Control vulnerability
PKSA-2mm6-m84c-116j CVE-2023-2104 GHSA-fc4g-f42p-7rhp
Affected version: <=1.4.3
Reported by:
GitHub -
[MEDIUM] alextselegidis/easyappointments vulnerable to Stored Cross-site Scripting
PKSA-4ky5-ksg8-41jb CVE-2023-2103 GHSA-7m8r-gmc3-3p4v
Affected version: <=1.4.3
Reported by:
GitHub -
[HIGH] Code Injection in alextselegidis/easyappointments
PKSA-xcq3-bw37-r5rt CVE-2023-1367 GHSA-9qvw-fhj2-xqmv
Affected version: <1.5.0
Reported by:
GitHub -
[CRITICAL] Easy!Appointments uses hard-coded credentials
PKSA-h83m-6xpp-14tj CVE-2023-1269 GHSA-347f-rxg8-qgrv
Affected version: <=1.4.3
Reported by:
GitHub -
[HIGH] Privilege escalation in easyappointments
PKSA-2mgs-m1qn-58px CVE-2022-1397 GHSA-7f62-4887-cfv5
Affected version: <=1.4.3
Reported by:
GitHub -
[CRITICAL] Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
PKSA-z6c9-mttf-fr49 CVE-2022-0482 GHSA-r6cm-wg48-rh2r
Affected version: <1.4.3
Reported by:
GitHub