Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

easyappointments — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in easyappointments, with AI-generated Chinese analysis, references, and POCs.

This page provides aggregated vulnerability data for the easyappointments product, focusing on common weakness classifications and associated security tags. It compiles a comprehensive collection of reported security flaws, including injection flaws, cross-site scripting issues, and authentication bypasses, covering incidents disclosed from its initial release through the most recent updates. Users can utilize this resource to track the vendor's security advisory history, gain a deeper understanding of specific weakness classes affecting web-based appointment scheduling software, and review the complete vulnerability timeline for easyappointments. The aggregation aims to provide transparency regarding the security posture of the application by centralizing disparate reports into a single, accessible view. This allows security professionals, developers, and system administrators to assess the risk landscape accurately without navigating multiple disparate sources. By organizing these findings chronologically and categorically, the page facilitates better decision-making regarding patching priorities and mitigation strategies. It serves as a reference point for evaluating the stability and security maintenance practices of the easyappointments project over time. Readers can identify patterns in how vulnerabilities are discovered and resolved, offering insights into the overall development lifecycle security. This centralized view helps in correlating specific weakness types with particular versions or components of the product. The information is presented to support informed risk management and to highlight areas that may require immediate attention or further scrutiny by the community.

Vendor: alextselegidis

CVE IDTitleCVSSSeverityPublished
CVE-2026-55651 Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure CWE-200 7.1 High2026-07-14
CVE-2026-52841 Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync CWE-639 3.1 Low2026-07-14
CVE-2026-52840 Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network CWE-918 2.7 Low2026-07-14
CVE-2026-52839 Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass CWE-639 3.3 Low2026-07-14
CVE-2026-52838 Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS CWE-79 2.6 Low2026-07-14
CVE-2026-52837 Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page CWE-200 6.9 Medium2026-07-14
CVE-2026-23622 CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover CWE-352 8.8AIHighAI2026-01-15
CVE-2023-3288 A BOLA vulnerability in POST /providers in EasyAppointments < 1.5.0 CWE-639 8.5 High2024-07-09
CVE-2023-38055 A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} in EasyAppointments < 1.5.0 CWE-639 9.6 Critical2024-07-09
CVE-2023-38054 A BOLA vulnerability in GET, PUT, DELETE /customers/{customerId} in EasyAppointments < 1.5.0 CWE-639 9.9 Critical2024-07-09
CVE-2023-38053 A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} in EasyAppointments < 1.5.0 CWE-639 9.9 Critical2024-07-09
CVE-2023-38052 A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} in EasyAppointments < 1.5.0 CWE-639 9.9 Critical2024-07-09
CVE-2023-38051 A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} in EasyAppointments < 1.5.0 CWE-639 9.9 Critical2024-07-09
CVE-2023-38050 A BOLA vulnerability in GET, PUT, DELETE /webhooks/{webhookId} in EasyAppointments < 1.5.0 CWE-639 9.1 Critical2024-07-09
CVE-2023-38049 A BOLA vulnerability in GET, PUT, DELETE /appointments/{appointmentId} in EasyAppointments < 1.5.0 CWE-639 9.9 Critical2024-07-09
CVE-2023-38048 A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} in EasyAppointments < 1.5.0 CWE-639 9.9 Critical2024-07-09
CVE-2023-38047 A BOLA vulnerability in GET, PUT, DELETE /categories/{categoryId} in EasyAppointments < 1.5.0. CWE-639 8.5 High2024-07-09
CVE-2023-3289 A BOLA vulnerability in POST /services in EasyAppointments < 1.5.0 CWE-639 7.7 High2024-07-09
CVE-2023-3290 A BOLA vulnerability in POST /customers in EasyAppointments < 1.5.0 CWE-639 5.0 Medium2024-07-09
CVE-2023-3286 A BOLA vulnerability in POST /secretaries in EasyAppointments < 1.5.0 CWE-639 7.7 High2024-07-09
CVE-2023-3287 A BOLA vulnerability in POST /admins in EasyAppointments < 1.5.0 CWE-639 9.9 Critical2024-07-09
CVE-2023-3285 A BOLA vulnerability in POST /appointments in EasyAppointments < 1.5.0 CWE-639 7.7 High2024-07-09

All 22 known CVE vulnerabilities affecting easyappointments with full Chinese analysis, references, and POCs where available.