cbcvebase.

Nsquared Simply Schedule Appointments vulnerabilities

11 known vulnerabilities affecting nsquared/simply_schedule_appointments.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2026-39493P2CRITICALCVSS 9.3≥ n/a, ≤ 1.6.9.272026-06-15
CVE-2026-39493 [CRITICAL] CWE-89 CVE-2026-39493: Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
nvd
CVE-2026-39495P3HIGHCVSS 8.5≤ 1.6.9.272026-04-08
CVE-2026-39495 [HIGH] CWE-89 CVE-2026-39495: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blind SQL Injection.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.27.
nvd
CVE-2024-2342P3HIGHCVSS 8.8fixed in 1.6.7.92024-04-09
CVE-2024-2342 [HIGH] CWE-89 CVE-2024-2342: The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the customer_id parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a
nvd
CVE-2026-42384P3HIGHCVSS 7.5≥ n/a, < 1.6.11.22026-06-15
CVE-2026-42384 [HIGH] CWE-201 CVE-2026-42384: Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions. Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
nvd
CVE-2024-2341P3MEDIUMCVSS 6.5fixed in 1.6.7.92024-04-09
CVE-2024-2341 [MEDIUM] CWE-89 CVE-2024-2341: The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and including, 1.6.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen
nvd
CVE-2025-69315P3MEDIUMCVSS 6.5≤ 1.6.9.152026-01-22
CVE-2025-69315 [MEDIUM] CWE-862 CVE-2025-69315: Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appoint Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.9.15.
nvd
CVE-2026-57317P4HIGHCVSS 7.1≥ n/a, ≤ 1.6.12.22026-06-26
CVE-2026-57317 [HIGH] CWE-79 CVE-2026-57317: Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
nvd
CVE-2026-39447P4HIGHCVSS 7.1≥ n/a, ≤ 1.6.10.62026-06-15
CVE-2026-39447 [HIGH] CWE-79 CVE-2026-39447: Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions. Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.
nvd
CVE-2026-39694P4MEDIUMCVSS 5.3≤ 1.6.10.22026-04-08
CVE-2026-39694 [MEDIUM] CWE-862 CVE-2026-39694: Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appoint Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2.
nvd
CVE-2024-4288P4MEDIUMCVSS 5.4fixed in 1.6.7.182024-05-16
CVE-2024-4288 [MEDIUM] CWE-79 CVE-2024-4288: The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permiss
nvd
CVE-2024-1760P4MEDIUMCVSS 4.7fixed in 1.6.6.242024-03-06
CVE-2024-1760 [MEDIUM] CWE-352 CVE-2024-1760: The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.6.20. This is due to missing or incorrect nonce validation on the ssa_factory_reset() function. This makes it possible for unauthenticated attackers to reset the plugin
nvd