alextselegidis/easyappointments Security Advisories for 1.5.2 (7)
-
[LOW] Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
PKSA-qjn8-scvh-tqz1 CVE-2026-52838 GHSA-996f-334j-67g7
Affected version: <=1.5.2
Reported by:
GitHub -
[LOW] Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
PKSA-4qd5-bb9g-9x8d CVE-2026-52841 GHSA-8hm4-r66f-29wr
Affected version: <=1.5.2
Reported by:
GitHub -
[MEDIUM] Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
PKSA-nm1q-gc5c-m98k CVE-2026-52837 GHSA-xgr6-pqjv-3pf8
Affected version: <=1.5.2
Reported by:
GitHub -
[LOW] Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
PKSA-9k3m-y8wr-wv52 CVE-2026-52839 GHSA-w8xc-8g92-v77h
Affected version: <=1.5.2
Reported by:
GitHub -
[LOW] Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
PKSA-qvhv-yhm7-8xkk CVE-2026-52840 GHSA-pm5p-7w5h-jm5q
Affected version: <=1.5.2
Reported by:
GitHub -
[HIGH] Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
PKSA-hmm5-v3nr-ydfq CVE-2026-55651 GHSA-4vmm-5qvc-w5p7
Affected version: =1.5.2
Reported by:
GitHub -
[HIGH] alextselegidis/easyappointments is Vulnerable to CSRF Protection Bypass
PKSA-wm96-drjh-4138 CVE-2026-23622 GHSA-54v4-4685-vwrj
Affected version: <=1.5.2
Reported by:
GitHub