Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

alextselegidis — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting alextselegidis. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Alex Tselegidis is primarily associated with web application development, focusing on creating user-friendly interfaces and functionality. Historically, vulnerabilities attributed to this researcher include cross-site scripting (XSS), remote code execution (RCE), and privilege escalation, often stemming from input validation failures and insecure direct object references. Security analysis reveals a pattern of identifying flaws in content management systems and e-commerce platforms, with some discoveries leading to significant security advisories. While no major public incidents are directly linked, the consistent discovery of critical vulnerabilities across multiple platforms demonstrates a notable impact on web security landscapes, particularly in open-source and commercial web applications.

CVE ID Title CVSS Severity Published
CVE-2026-73529 Plainpad Missing Rate Limiting via POST /v1/sessions — plainpad CWE-307 5.3 Medium 2026-08-18
CVE-2026-55651 Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure — easyappointments CWE-200 7.1 High 2026-07-14
CVE-2026-52841 Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync — easyappointments CWE-639 3.1 Low 2026-07-14
CVE-2026-52840 Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network — easyappointments CWE-918 2.7 Low 2026-07-14
CVE-2026-52839 Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass — easyappointments CWE-639 3.3 Low 2026-07-14
CVE-2026-52838 Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS — easyappointments CWE-79 2.6 Low 2026-07-14
CVE-2026-52837 Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page — easyappointments CWE-200 6.9 Medium 2026-07-14
CVE-2026-42562 Plainpad: Privilege Escalation via Writable Admin Field in Profile Update (Access Control) — plainpad CWE-269 8.3 High 2026-05-09
CVE-2026-23622 CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover — easyappointments CWE-352 8.8AI High AI 2026-01-15
CVE-2025-31828 WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability — Easy!Appointments CWE-352 4.3 Medium 2025-04-01
CVE-2024-0698 Easy!Appointments <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting — Easy!Appointments CWE-79 6.4 Medium 2024-03-05
CVE-2023-3700 Authorization Bypass Through User-Controlled Key in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-639 6.3 Medium 2023-07-17
CVE-2023-3568 Open Redirect in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-601 6.3 Medium 2023-07-10
CVE-2023-2105 Session Fixation in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-384 8.1 - 2023-04-15
CVE-2023-2103 Cross-site Scripting (XSS) - Stored in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-79 5.4 - 2023-04-15
CVE-2023-2102 Cross-site Scripting (XSS) - Stored in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-79 5.4 - 2023-04-15
CVE-2023-2104 Improper Access Control in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-284 5.4 - 2023-04-15
CVE-2023-1367 Code Injection in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-94 3.8 - 2023-03-13
CVE-2023-1269 Use of Hard-coded Credentials in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-798 9.8 - 2023-03-08
CVE-2022-1397 API Privilege Escalation in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-269 8.8 - 2022-05-10
CVE-2022-0482 Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments — alextselegidis/easyappointments CWE-359 7.5 - 2022-03-09

This page lists every published CVE security advisory associated with alextselegidis. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.