Nsquared's vulnerability footprint centers on web-based appointment and scheduling applications, with the durable signal focused on application-layer input-handling weaknesses including cross-site scripting, SQL injection, and cross-site request forgery. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nsquared over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39493CRITICAL Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions. | Jun 15, 2026 | 9.3 | 32 | NO | NO |
CVE-2026-59523MEDIUM Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.Th | Jul 13, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-57812MEDIUM Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.Th | Jul 13, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-57317HIGH Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions. | Jun 26, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-39495HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Blin | Apr 8, 2026 | 8.5 | 27 | NO | NO |
CVE-2026-42384HIGH Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions. | Jun 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-39447HIGH Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions. | Jun 15, 2026 | 7.1 | 25 | NO | NO |
CVE-2025-69315MEDIUM Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.Th | Jan 22, 2026 | 6.5 | 25 | NO | NO |
CVE-2024-2342HIGH The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the customer_id parameter in all versions up | Apr 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-2341MEDIUM The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the keys parameter in all versions up to, and | Apr 9, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nsquared.
Media articles that mention a CVE ID that affects a product developed by Nsquared — matched by CVE ID, not by vendor name.