Easy!Appointments
Open-source appointment scheduler for booking customer appointments online.
Easy!Appointments 1.6 lands video conferencing, GDPR tools, and a serious security overhaul across its CalDAV and booking stack.
◆Recent moves
- 5d ago
Easy!Appointments 1.6.1-beta.1: Security hardening and CalDAV polish
⚡ SPARK1.6.1-beta.1 closes a concentrated set of serious security vulnerabilities: LDAP injection in the directory search, SSRF via CalDAV URLs pointing into the local network, cross-account appointment takeover, provider Google Calendar tokens and CalDAV passwords leaking to secretary accounts, and CAPTCHA bypass — alongside a CalDAV UX overhaul that surfaces connection errors and hosts inline.
View source ↗ - 23d ago
1.6.1-alpha.1
1.6.1-alpha.1 is the security pre-release that preceded beta.1, shipping the core authorization fixes (CAPTCHA bypass, login throttling, appointment takeover, XSS via meeting link field) before the CalDAV and credential exposure patches landed in beta.1.
View source ↗ - 5mo ago
Easy!Appointments 1.6.0-beta.2: Video conferencing, CAPTCHA, GDPR, and CalDAV
⚡ SPARK1.6.0-beta.2 is the most complete pre-release of the 1.6 major version, introducing Jitsi and Google Meet video conference link generation, CAPTCHA and ALTCHA anti-abuse protection, GDPR tools, multi-date working plan exceptions, and a rebuilt CalDAV synchronization stack — the largest capability expansion in the product's visible history.
View source ↗ - 6mo ago
1.6.0-beta.1
1.6.0-beta.1 is an earlier pre-release tag carrying the same 1.6.0 feature set as beta.2 — no additional capabilities over the alpha; the features visible here were first introduced in alpha.1.
View source ↗ - 6mo ago
1.6.0-alpha.1
1.6.0-alpha.1 is the initial 1.6.0 alpha tag — the same feature list that appears in beta.1 and beta.2, published before community testing identified the bugs addressed in the beta series.
View source ↗ - 1y ago
1.5.2-beta.1
1.5.2-beta.1 (2025) addressed permission gaps in appointment search, webhook triggering on API-managed records, provider visibility on login, and email text/HTML parity — correctness fixes on the 1.5.x stable line while 1.6.0 was in development.
View source ↗