Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

appointment-booking-software — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in appointment-booking-software, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the appointment-booking-software product, categorized by Common Weakness Enumeration types and specific software tags. It aggregates a comprehensive collection of reported security flaws, ranging from SQL injection and cross-site scripting to authentication bypasses and insecure direct object references. The data covers vulnerability disclosures released from January 2018 through the present day, ensuring that both historical and recent security incidents are captured for thorough analysis. Visitors can use this resource to track a vendor's advisory history, understand the prevalence and impact of specific weakness classes within this software ecosystem, and look up a product's vulnerability history to assess its overall security posture. By centralizing this information, the page aims to provide developers, security analysts, and procurement teams with the context needed to evaluate risks and prioritize remediation efforts. Understanding the nature and frequency of these flaws helps stakeholders make informed decisions about software adoption and patch management strategies. This structured overview eliminates the need to search through disparate sources, offering a single point of reference for understanding the security landscape of appointment booking applications. The information presented is derived from public security advisories, CVE databases, and official vendor notifications, ensuring accuracy and reliability for professional use.

Vendor: open-reception

CVE ID Title CVSS Severity Published
CVE-2026-48088 OpenReception vulnerable to unauthenticated staff crypto poisoning that breaks E2E recipient directory CWE-862 9.4 Critical 2026-08-06
CVE-2026-48087 OpenReception: WebAuthn passkey injection allows account takeover CWE-287 9.8 Critical 2026-08-06
CVE-2026-48086 OpenReception: Tenant admin self-promotes to GLOBAL_ADMIN CWE-269 9.9 Critical 2026-08-06
CVE-2026-48085 OpenReception has unauthenticated GLOBAL_ADMIN account creation post-bootstrap CWE-862 9.8 Critical 2026-08-06
CVE-2026-48084 OpenReception doesn't rate limit passphrase login attempts CWE-307 7.4 High 2026-08-06
CVE-2026-48083 OpenReception: Unauthenticated POST /api/log accepts arbitrary content with CRLF injection and no size or rate limits CWE-117 6.5 Medium 2026-08-06
CVE-2026-48082 OpenReception's bootstrap challenge proof-of-work difficulty hardcoded to 16 bits, which enables abuse rate amplification CWE-770 3.7 Low 2026-08-06
CVE-2026-48081 OpenReception vulnerable to stored click-triggered XSS via javascript: tenant links rendered into patient-facing footer CWE-79 8.1 High 2026-08-06
CVE-2026-48079 OpenReception's logout page clears local access_token before server-side revocation, leaving duplicated tokens valid until expiry CWE-613 7.4 High 2026-08-06
CVE-2026-48078 OpenReception's schedule endpoint discloses isPublic=false channels and slot availability to unauthenticated callers CWE-200 5.3 Medium 2026-08-06
CVE-2026-48077 OpenReception: GET appointment by ID returns full appointment record without authorization CWE-862 5.3 Medium 2026-08-06
CVE-2026-48076 OpenReception's bootstrap booking flow allows unauthenticated booking on isPublic=false channels CWE-863 6.5 Medium 2026-08-06
CVE-2026-48075 OpenReception's unauthenticated add-to-tunnel endpoint accepts arbitrary appointment injections CWE-862 6.5 Medium 2026-08-06
CVE-2026-48074 OpenReception: Staff deletion removes pending invites cross-tenant by email match CWE-863 2.7 Low 2026-08-06
CVE-2026-48071 OpenReception's client PIN challenge throttle is keyed by emailHash only, allowing cross-tenant lockout CWE-307 5.8 Medium 2026-08-06
CVE-2026-48080 OpenReception's tenant detail endpoint discloses live PostgreSQL connection string, superuser-scoped in the tested official deployment CWE-200 8.0 High 2026-08-06

All 16 known CVE vulnerabilities affecting appointment-booking-software with full Chinese analysis, references, and POCs where available.