Easy!Appointments SQL injection vulnerability
Modified: 8/26/2025
package
pkg:packagist/alextselegidis/easyappointments
Easy!Appointments SQL injection vulnerability
Modified: 8/26/2025
Easy!Appointments uses hard-coded credentials
Modified: 11/8/2023
Remote code execution in alextselegidis/easyappointments
Modified: 3/24/2025
alextselegidis/easyappointments Session Fixation vulnerability
Modified: 11/8/2023
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
Modified: 7/29/2026
alextselegidis/easyappointments is Vulnerable to CSRF Protection Bypass
Modified: 2/3/2026
Privilege escalation in easyappointments
Modified: 11/8/2023
alextselegidis/easyappointments vulnerable to Stored Cross-site Scripting
Modified: 11/8/2023
Easy!Appointments Improper Access Control vulnerability
Modified: 2/16/2024
Easy!Appointments Improper Restriction of Excessive Authentication Attempts
Modified: 3/19/2025
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Modified: 7/29/2026
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Modified: 7/29/2026
Code Injection in alextselegidis/easyappointments
Modified: 11/8/2023
alextselegidis/easyappointments Improper Access Control vulnerability
Modified: 11/8/2023
Easy!Appointments Denial of Service (DoS)
Modified: 5/8/2025
alextselegidis/easyappointments vulnerable to Stored Cross-site Scripting
Modified: 11/8/2023
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Modified: 7/29/2026
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
Modified: 2/19/2024
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Modified: 7/29/2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Modified: 7/29/2026