Alex Tselegidis Easy!Appointments是Alex Tselegidis个人开发者的一个在线预约系统。 Alex Tselegidis Easy!Appointments 1.6.0之前版本存在跨站脚本漏洞,该漏洞源于booking settings页面中“booking disabled”消息存储后未进行转义或清理,可能导致经过身份验证的管理员存储HTML或JavaScript,并在启用禁用预订模式时触发存储型跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| alextselegidis | easyappointments | < 1.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| alextselegidis | easyappointments | < 1.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55651 | 7.1 HIGH | Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure |
| CVE-2026-52837 | 6.9 MEDIUM | Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page |
| CVE-2026-52839 | 3.3 LOW | Easy!Appointments appointments/store and appointments/update allow cross-provider appointm |
| CVE-2026-52841 | 3.1 LOW | Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend |
| CVE-2026-52840 | 2.7 LOW | Easy!Appointments has server-side request forgery in CalDAV connection test that exposes t |
No comments yet