Nsqua maintains a small portfolio of web-based scheduling and visual-content applications, with its vulnerability exposure centered on input-handling and access-control issues including cross-site scripting, SQL injection, and missing authorization controls. While the vendor's disclosures are modest in volume, they frequently acquire public exploit code, reflecting the typical appeal of web application flaws to security researchers and tooling developers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nsqua over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2373MEDIUM The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details suc | Aug 29, 2022 | 5.3 | 30 | NO | YES |
CVE-2024-7129HIGH The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploite | Sep 13, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-50851HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in N Squared Appointment Booking Calendar — Simply Schedule Appointments Booking | Dec 28, 2023 | 7.2 | 20 | NO | NO |
CVE-2022-2374MEDIUM The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform | Aug 29, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-7877MEDIUM The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, whic | Nov 5, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-7876MEDIUM The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, | Nov 5, 2024 | 4.8 | 16 | NO | NO |
CVE-2023-2764MEDIUM The Draw Attention plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_set_featured_image function in versions up | Jun 9, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nsqua.
Media articles that mention a CVE ID that affects a product developed by Nsqua — matched by CVE ID, not by vendor name.