If you discover a security vulnerability within Easy!Appointments, please send an email to info@easyappointments.org. All security vulnerabilities will be promptly addressed.
Security: alextselegidis/easyappointments
Security
.github/SECURITY.md
-
Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google syncGHSA-8hm4-r66f-29wr published
Jun 15, 2026 by alextselegidisLow -
Server-side request forgery in CalDAV connection test exposes the deployment's internal networkGHSA-pm5p-7w5h-jm5q published
Jun 15, 2026 by alextselegidisLow -
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization BypassGHSA-w8xc-8g92-v77h published
Jun 15, 2026 by alextselegidisLow -
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSSGHSA-996f-334j-67g7 published
Jun 15, 2026 by alextselegidisLow -
Unauthenticated customer PII disclosure on booking reschedule pageGHSA-xgr6-pqjv-3pf8 published
Jun 15, 2026 by alextselegidisModerate -
Appointments Takeover via Excessive Data ExposureGHSA-4vmm-5qvc-w5p7 published
Jun 15, 2026 by alextselegidisHigh -
CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeoverGHSA-54v4-4685-vwrj published
Jan 15, 2026 by alextselegidisModerate
Learn more about advisories related to alextselegidis/easyappointments in the GitHub Advisory Database