PT-2026-33764 · Nsquared · Simply Schedule Appointments

Published

2026-04-20

·

Updated

2026-06-15

·

CVE-2026-39493

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions Simply Schedule Appointments versions prior to 1.6.9.28
Description An unauthenticated SQL Injection exists in the software, allowing an attacker to execute arbitrary SQL queries without needing to log in. SQL Injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update to a version newer than 1.6.9.27.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39493

Affected Products

Simply Schedule Appointments