Technology · Packagist
alextselegidis/easyappointments (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in alextselegidis/easyappointments (Packagist): 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55651, was published on 14 July 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 0
- Exploited in the wild
- 0
About alextselegidis/easyappointments (Packagist)
EasyAppointments is an open-source web application for handling automated appointment scheduling.
Latest alextselegidis/easyappointments (Packagist) vulnerabilities
- CVE-2026-55651: Easy!Appointments excessive data exposure in customer searchhighCVSS 7.1EPSS 0.3%
- CVE-2026-52841: Easy!Appointments authorization bypass in Google OAuth provider bindinglowCVSS 3.1EPSS 0.2%
- CVE-2026-52840: alextselegidis Easy!Appointments SSRF in CalDAV connection testlowCVSS 3.1EPSS 0.3%
- CVE-2026-52839: Easy!Appointments authorization bypass in appointment store and updatelowCVSS 3.3EPSS 0.2%
- CVE-2026-52838: Easy!Appointments stored XSS in booking disabled messagelowCVSS 3.1EPSS 0.2%
- CVE-2026-52837: alextselegidis Easy!Appointments information disclosure in reschedule viewmediumCVSS 4EPSS 0.6%
- CVE-2026-23622: alextselegidis/easyappointments is Vulnerable to CSRF Protection BypassmediumCVSS 4EPSS 0.2%
- CVE-2025-50383: alextselegidis Easy!Appointments SQL injection in order_by parameterhighCVSS 8.1EPSS 0.4%
- CVE-2025-29448: Easy!Appointments Denial of Service (DoS)mediumCVSS 4EPSS 0.6%
- CVE-2024-57602: Easy!Appointments Improper Restriction of Excessive Authentication AttemptslowCVSS 3.1EPSS 0.8%
- CVE-2024-57601: Remote code execution in alextselegidis/easyappointmentslowCVSS 3.1EPSS 0.5%
- CVE-2023-3700: Easy!Appointments Improper Access Control vulnerabilitylowCVSS 3EPSS 0.4%
- CVE-2023-2102: alextselegidis/easyappointments vulnerable to Stored Cross-site ScriptinglowCVSS 3EPSS 0.5%
- CVE-2023-2103: alextselegidis/easyappointments vulnerable to Stored Cross-site ScriptinglowCVSS 3.1EPSS 0.5%
- CVE-2023-2104: alextselegidis/easyappointments Improper Access Control vulnerabilitylowCVSS 3EPSS 0.4%
- CVE-2023-2105: alextselegidis/easyappointments Session Fixation vulnerabilitylowCVSS 3EPSS 0.7%
- CVE-2023-1367: Code Injection in alextselegidis/easyappointmentslowCVSS 3.1EPSS 0.4%
- CVE-2023-1269: Easy!Appointments uses hard-coded credentialslowCVSS 3.1EPSS 0.7%
- CVE-2022-1397: Privilege escalation in easyappointmentslowCVSS 3.1EPSS 1.1%
- CVE-2022-0482: Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentslowCVSS 3.1EPSS 43.8%
Most severe alextselegidis/easyappointments (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-50383: alextselegidis Easy!Appointments SQL injection in order_by parameterhighCVSS 8.1EPSS 0.4%
- CVE-2026-55651: Easy!Appointments excessive data exposure in customer searchhighCVSS 7.1EPSS 0.3%
- CVE-2026-52837: alextselegidis Easy!Appointments information disclosure in reschedule viewmediumCVSS 4EPSS 0.6%
- CVE-2025-29448: Easy!Appointments Denial of Service (DoS)mediumCVSS 4EPSS 0.6%
- CVE-2026-23622: alextselegidis/easyappointments is Vulnerable to CSRF Protection BypassmediumCVSS 4EPSS 0.2%
- CVE-2026-52839: Easy!Appointments authorization bypass in appointment store and updatelowCVSS 3.3EPSS 0.2%
- CVE-2022-0482: Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentslowCVSS 3.1EPSS 43.8%
- CVE-2022-1397: Privilege escalation in easyappointmentslowCVSS 3.1EPSS 1.1%
- CVE-2024-57602: Easy!Appointments Improper Restriction of Excessive Authentication AttemptslowCVSS 3.1EPSS 0.8%
- CVE-2023-1269: Easy!Appointments uses hard-coded credentialslowCVSS 3.1EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 6 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/alextselegidis-easyappointments.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "alextselegidis/easyappointments (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/alextselegidis-easyappointments, 27 September 2026.