EasyappointmentsCVEs & Vulnerabilities

34 CVEs affecting Easyappointments products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

easyappointments 25easy\!appointments 11
CVE-2022-0482KEVCRITICALin the wild

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

11 Apr 2026
9.1
CVSS
CVE-2026-23622HIGH

Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or $_REQUEST), so an attacker can perform CSRF by forcing a victim's browser to issue a crafted GET request. Impact: creation of admin accounts, modification of admin email/password, and full admin account takeover.

15 Jan 2026
8.8
CVSS
CVE-2025-50383HIGH

alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.

25 Aug 2025
8.1
CVSS
CVE-2025-29448HIGH

Booking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations, causing a denial of service by blocking all future booking availability.

7 May 2025
7.5
CVSS
CVE-2025-31828HIGH

Cross-Site Request Forgery (CSRF) vulnerability in alextselegidis Easy!Appointments easyappointments allows Cross Site Request Forgery.This issue affects Easy!Appointments: from n/a through <= 1.4.2.

1 Apr 2025
8.8
CVSS
CVE-2024-57602CRITICAL

An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.

13 Feb 2025
9.8
CVSS
CVE-2024-57601MEDIUM

Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.

13 Feb 2025
6.1
CVSS
CVE-2023-3290MEDIUM

A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation.

9 Jul 2024
5.0
CVSS
CVE-2023-3289MEDIUM

A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.

9 Jul 2024
6.5
CVSS
CVE-2023-3288HIGH

A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation.

9 Jul 2024
8.8
CVSS
CVE-2023-3287HIGH

A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege escalation.

9 Jul 2024
8.8
CVSS
CVE-2023-3286MEDIUM

A BOLA vulnerability in POST /secretaries allows a low privileged user to create a low privileged user (secretary) in the system. This results in unauthorized data manipulation.

9 Jul 2024
6.5
CVSS
CVE-2023-38055HIGH

A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-38054HIGH

A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} allows a low privileged user to fetch, modify or delete a low privileged user (customer). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-38053HIGH

A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-38052HIGH

A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-38051HIGH

A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (secretary). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-38050HIGH

A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} allows a low privileged user to fetch, modify or delete a webhook of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-38049HIGH

A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} allows a low privileged user to fetch, modify or delete an appointment of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-38048HIGH

A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-38047HIGH

A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} allows a low privileged user to fetch, modify or delete the category of any user (including admin). This results in unauthorized access and unauthorized data manipulation.

9 Jul 2024
8.1
CVSS
CVE-2023-32295MEDIUM

Missing Authorization vulnerability in Alex Tselegidis Easy!Appointments.This issue affects Easy!Appointments: from n/a through 1.3.3.

11 Apr 2024
6.3
CVSS
CVE-2024-0698MEDIUM

The Easy!Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easyappointments' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

5 Mar 2024
5.4
CVSS
CVE-2023-3700MEDIUM

Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

17 Jul 2023
4.3
CVSS
CVE-2023-2105HIGH

Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

15 Apr 2023
8.8
CVSS
CVE-2023-2104MEDIUM

Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

15 Apr 2023
5.4
CVSS
CVE-2023-2103MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

15 Apr 2023
5.4
CVSS
CVE-2023-2102MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

15 Apr 2023
4.8
CVSS
CVE-2023-1367LOW

Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

13 Mar 2023
3.8
CVSS
CVE-2023-1269CRITICAL

Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

8 Mar 2023
9.8
CVSS
CVE-2022-1397HIGH

API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover.

10 May 2022
8.8
CVSS
CVE-2018-13063HIGH

Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.

16 Mar 2020
7.5
CVSS
CVE-2018-13060MEDIUM

Easy!Appointments 1.3.0 has a Guessable CAPTCHA issue.

16 Mar 2020
6.5
CVSS
CVE-2019-14936MEDIUM

Easy!Appointments 1.3.2 plugin for WordPress allows Sensitive Information Disclosure (Username and Password Hash).

11 Sep 2019
5.3
CVSS
← PrevPage 1 / 1Next →