VendorsIqonickivicareall versions
Vulnerabilities

Iqonic Design Kivicare

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2022-0786
KiviCare < 2.3.9 - Unauthenticated SQLi
Published 2022-06-13 · Modified
9.8EPSS 0.133
CVE-2025-1572
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.7 - Authenticated (Doctor+) SQL Injection via 'u_id' Parameter
Published 2025-02-28 · Analyzed
8.8EPSS 0.005
CVE-2023-2628
KiviCare Management System < 3.2.1 - Multiple CSRF
Published 2023-06-27 · Modified
8.8EPSS 0.004
CVE-2024-35659
WordPress KiviCare plugin <= 3.6.6 - Insecure Direct Object References (IDOR) vulnerability
Published 2024-06-08 · Modified
8.8EPSS 0.003
CVE-2024-11728
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection
Published 2024-12-06 · Analyzed
7.51 PoCEPSS 0.136
CVE-2023-2623
KiviCare Management System < 3.2.1 - Subscriber+ Sensitive Information Disclosure
Published 2023-06-27 · Modified
6.5EPSS 0.008
CVE-2024-11729
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Authenticated (Subscriber+) SQL Injection
Published 2024-12-06 · Analyzed
6.5EPSS 0.006
CVE-2024-11730
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Authenticated (Doctor/Receptionist+) SQL Injection
Published 2024-12-06 · Analyzed
6.5EPSS 0.004
CVE-2023-2624
KiviCare Management System < 3.2.1 - Reflected Cross-Site Scripting
Published 2023-06-27 · Modified
6.1EPSS 0.012
CVE-2023-2627
KiviCare Management System < 3.2.1 - Subscriber+ Unauthorised AJAX Calls
Published 2023-06-27 · Modified
4.3EPSS 0.002