Vulnerabilidades en alextselegidis

20 resultados
Análisis Vexday

O fornecedor alextselegidis acumula 20 vulnerabilidades no Vexday, com 7 divulgadas nos últimos 90 dias, indicando atividade contínua de descoberta. Nenhuma vulnerabilidade está sob ataque ativo no momento (KEV=0) e apenas 1 é crítica, reduzindo o risco imediato. A fraqueza dominante é controle de autorização inadequado (CWE-639), sugerindo problemas estruturais de segurança que demandam revisão de políticas de acesso.

CVE-2022-0482CRITICALExposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentsEPSS 43.7%CVE-2022-1397HIGHAPI Privilege Escalation in alextselegidis/easyappointmentsEPSS 1.1%CVE-2023-1269MEDIUMUse of Hard-coded Credentials in alextselegidis/easyappointmentsEPSS 0.7%CVE-2023-2105HIGHSession Fixation in alextselegidis/easyappointmentsEPSS 0.7%CVE-2023-2102MEDIUMCross-site Scripting (XSS) - Stored in alextselegidis/easyappointmentsEPSS 0.5%CVE-2023-2103MEDIUMCross-site Scripting (XSS) - Stored in alextselegidis/easyappointmentsEPSS 0.5%CVE-2023-2104MEDIUMImproper Access Control in alextselegidis/easyappointmentsEPSS 0.4%CVE-2023-3700MEDIUMAuthorization Bypass Through User-Controlled Key in alextselegidis/easyappointmentsEPSS 0.4%CVE-2023-3568MEDIUMOpen Redirect in alextselegidis/easyappointmentsEPSS 0.4%CVE-2023-1367MEDIUM Code Injection in alextselegidis/easyappointmentsEPSS 0.4%CVE-2024-0698MEDIUMEasy!Appointments <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.4%CVE-2026-52837MEDIUMEasy!Appointments has unauthenticated customer PII disclosure on booking reschedule pageEPSS 0.4%CVE-2026-42562HIGHPlainpad: Privilege Escalation via Writable Admin Field in Profile Update (Access Control)EPSS 0.3%CVE-2025-31828MEDIUMWordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerabilityEPSS 0.2%CVE-2026-23622HIGHCSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeoverEPSS 0.2%CVE-2026-52840LOWEasy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal networkEPSS 0.2%CVE-2026-55651HIGHEasy!Appointments Vulnerable to Appointments Takeover via Excessive Data ExposureEPSS 0.2%CVE-2026-52838LOWEasy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSSEPSS 0.2%CVE-2026-52839LOWEasy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization BypassEPSS 0.1%CVE-2026-52841LOWEasy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google syncEPSS 0.1%