Loading HuntDB...

easyappointments

1 Product 8 CVEs

CVE Severity Distribution (All Time)

Critical
6
High
1
Medium
1
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

CVE-2023-38055 CRITICAL 1 year ago

A BOLA vulnerability in GET, PUT, DELETE /services/{serviceId} allows a low privileged user to fetch, modify or delete the services of any user (incl…

CVE-2023-38053 CRITICAL 1 year ago

A BOLA vulnerability in GET, PUT, DELETE /settings/{settingName} allows a low privileged user to fetch, modify or delete the settings of any user (in…

CVE-2023-38052 CRITICAL 1 year ago

A BOLA vulnerability in GET, PUT, DELETE /admins/{adminId} allows a low privileged user to fetch, modify or delete a high privileged user (admin). Th…

CVE-2023-38051 CRITICAL 1 year ago

A BOLA vulnerability in GET, PUT, DELETE /secretaries/{secretaryId} allows a low privileged user to fetch, modify or delete a low privileged user (se…

CVE-2023-38048 CRITICAL 1 year ago

A BOLA vulnerability in GET, PUT, DELETE /providers/{providerId} allows a low privileged user to fetch, modify or delete a privileged user (provider)…

CVE-2023-3289 HIGH 1 year ago

A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in…

CVE-2023-3287 CRITICAL 1 year ago

A BOLA vulnerability in POST /admins allows a low privileged user to create a high privileged user (admin) in the system. This results in privilege e…

CVE-2024-2844 MEDIUM 1 year, 4 months ago

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user validation on the ajax_cancel_…