← Back to all sparks
E

Easy!Appointments

CRM
Velocity6.3

Open-source appointment scheduler for booking customer appointments online.

Easy!Appointments 1.6 lands video conferencing, GDPR tools, and a serious security overhaul across its CalDAV and booking stack.

open-sourceschedulingcaldavvideo-conferencinggdprsecurity
Current state
Easy!Appointments, an open-source self-hosted scheduler, is shipping its 1.6 major version through a long pre-release cycle that has introduced Jitsi and Google Meet integration, CAPTCHA and ALTCHA anti-abuse protection, GDPR features, and a rebuilt CalDAV synchronization stack. The 1.6.1 security hardening pre-release then landed a concentrated batch of serious vulnerability fixes: LDAP injection in directory search, SSRF in CalDAV URL handling, cross-account appointment takeover, provider credential exposure to secretary accounts, and CAPTCHA bypass — a set that suggests the expanded surface area of 1.6.0 brought corresponding security debt.
Where it's heading
The 1.6 release line is expanding Easy!Appointments from a simple booking page into a more complete scheduling platform: video conferencing links, richer calendar sync, GDPR compliance tooling, and hardened multi-provider access controls all move it closer to commercial alternatives. The security work in 1.6.1-beta.1 is as important as the features — self-hosted deployments that serve real customer data need these fixes before anyone should run 1.6 in production.
Prediction
A stable 1.6.1 release is the next step, clearing the pre-release label once the security fixes are confirmed across the beta testing community. After that, the CalDAV and video conferencing integrations will likely expand — CalDAV push notifications or two-way Google Calendar sync are the natural follow-ons.

Recent moves

  1. 5d ago

    Easy!Appointments 1.6.1-beta.1: Security hardening and CalDAV polish

    ⚡ SPARK

    1.6.1-beta.1 closes a concentrated set of serious security vulnerabilities: LDAP injection in the directory search, SSRF via CalDAV URLs pointing into the local network, cross-account appointment takeover, provider Google Calendar tokens and CalDAV passwords leaking to secretary accounts, and CAPTCHA bypass — alongside a CalDAV UX overhaul that surfaces connection errors and hosts inline.

    View source ↗
  2. 23d ago

    1.6.1-alpha.1

    1.6.1-alpha.1 is the security pre-release that preceded beta.1, shipping the core authorization fixes (CAPTCHA bypass, login throttling, appointment takeover, XSS via meeting link field) before the CalDAV and credential exposure patches landed in beta.1.

    View source ↗
  3. 5mo ago

    Easy!Appointments 1.6.0-beta.2: Video conferencing, CAPTCHA, GDPR, and CalDAV

    ⚡ SPARK

    1.6.0-beta.2 is the most complete pre-release of the 1.6 major version, introducing Jitsi and Google Meet video conference link generation, CAPTCHA and ALTCHA anti-abuse protection, GDPR tools, multi-date working plan exceptions, and a rebuilt CalDAV synchronization stack — the largest capability expansion in the product's visible history.

    View source ↗
  4. 6mo ago

    1.6.0-beta.1

    1.6.0-beta.1 is an earlier pre-release tag carrying the same 1.6.0 feature set as beta.2 — no additional capabilities over the alpha; the features visible here were first introduced in alpha.1.

    View source ↗
  5. 6mo ago

    1.6.0-alpha.1

    1.6.0-alpha.1 is the initial 1.6.0 alpha tag — the same feature list that appears in beta.1 and beta.2, published before community testing identified the bugs addressed in the beta series.

    View source ↗
  6. 1y ago

    1.5.2-beta.1

    1.5.2-beta.1 (2025) addressed permission gaps in appointment search, webhook triggering on API-managed records, provider visibility on login, and email text/HTML parity — correctness fixes on the 1.5.x stable line while 1.6.0 was in development.

    View source ↗