CVE-2026-94673
- EPSS 0.25%
- Veröffentlicht 30.09.2026 12:27:11
- Zuletzt bearbeitet 30.09.2026 14:17:49
Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.
CVE-2026-94074
- EPSS 0.21%
- Veröffentlicht 30.09.2026 12:26:57
- Zuletzt bearbeitet 30.09.2026 14:17:37
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
CVE-2026-84764
- EPSS 0.14%
- Veröffentlicht 02.09.2026 11:37:33
- Zuletzt bearbeitet 04.09.2026 03:17:45
Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.
CVE-2026-65513
- EPSS 0.18%
- Veröffentlicht 06.08.2026 14:27:26
- Zuletzt bearbeitet 12.08.2026 20:58:37
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65508
- EPSS 0.29%
- Veröffentlicht 06.08.2026 14:27:24
- Zuletzt bearbeitet 12.08.2026 20:59:00
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-59523
- EPSS 0.16%
- Veröffentlicht 13.07.2026 08:41:25
- Zuletzt bearbeitet 09.10.2026 17:16:47
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through 1.6.11...
CVE-2026-57812
- EPSS 0.19%
- Veröffentlicht 13.07.2026 08:41:25
- Zuletzt bearbeitet 13.07.2026 16:57:56
Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6...
CVE-2026-57317
- EPSS 0.23%
- Veröffentlicht 26.06.2026 14:52:58
- Zuletzt bearbeitet 26.06.2026 18:17:03
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
CVE-2026-42384
- EPSS 0.29%
- Veröffentlicht 15.06.2026 20:18:33
- Zuletzt bearbeitet 15.06.2026 21:24:32
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
CVE-2026-39493
- EPSS 0.36%
- Veröffentlicht 15.06.2026 20:17:53
- Zuletzt bearbeitet 15.06.2026 21:24:32
Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.