VDB
Sign up

package

Packagist/alextselegidis/easyappointments

pkg:packagist/alextselegidis/easyappointments

LOW3.1Packagist
GHSA-8hm4-r66f-29wr· CVE-2026-52841

Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync

Modified: 7/29/2026

LOW2.7Packagist
GHSA-pm5p-7w5h-jm5q· CVE-2026-52840

Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network

Modified: 7/29/2026

LOW3.3Packagist
GHSA-w8xc-8g92-v77h· CVE-2026-52839

Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass

Modified: 7/29/2026