CVE-2026-39694
- EPSS 0.03%
- Veröffentlicht 08.04.2026 08:30:45
- Zuletzt bearbeitet 08.04.2026 21:26:13
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6...
CVE-2026-39495
- EPSS 0.03%
- Veröffentlicht 08.04.2026 08:30:12
- Zuletzt bearbeitet 10.04.2026 19:16:25
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from ...
CVE-2025-69315
- EPSS 0.04%
- Veröffentlicht 22.01.2026 16:52:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6...
CVE-2024-4288
- EPSS 0.27%
- Veröffentlicht 16.05.2024 11:15:48
- Zuletzt bearbeitet 08.04.2026 18:21:44
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitizatio...
CVE-2024-2341
- EPSS 0.56%
- Veröffentlicht 09.04.2024 19:15:32
- Zuletzt bearbeitet 08.04.2026 19:21:05
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied ...
CVE-2024-2342
- EPSS 0.48%
- Veröffentlicht 09.04.2024 19:15:32
- Zuletzt bearbeitet 08.04.2026 17:18:33
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the customer_id parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user su...
CVE-2024-22311
- EPSS 0.2%
- Veröffentlicht 27.03.2024 06:15:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N Squared Simply Schedule Appointments allows Reflected XSS.This issue affects Simply Schedule Appointments: from n/a through 1.6.6.20.
CVE-2024-1760
- EPSS 0.13%
- Veröffentlicht 06.03.2024 06:15:49
- Zuletzt bearbeitet 08.04.2026 17:18:24
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on th...