CVE-2026-23622
Severity CVSS v4.0:
HIGH
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
15/01/2026
Last modified:
28/01/2026
Description
Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF for POST requests and returns early for non-POST methods. Several application endpoints perform state-changing operations while accepting parameters from GET (or $_REQUEST), so an attacker can perform CSRF by forcing a victim's browser to issue a crafted GET request. Impact: creation of admin accounts, modification of admin email/password, and full admin account takeover.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:easyappointments:easy\!appointments:*:*:*:*:*:-:*:* | 1.5.2 (including) |
To consult the complete list of CPE names with products and versions, see this page



