Home/Product/iqonic kivicare
Product

iqonic kivicare

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-1572
< 3.6.8
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ par
6.5MEDIUM
CVE-2024-11730
< 3.6.5
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' param
6.5MEDIUM
CVE-2024-11729
<= 3.6.5
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[
6.5MEDIUM
CVE-2024-11728
<= 3.6.5
The KiviCare - Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[se
7.5HIGH
CVE-2024-35659
<= 3.6.4
Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Conf
5.3MEDIUM
CVE-2023-2628
< 3.2.1
The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions
8.8HIGH
CVE-2023-2627
< 3.2.1
The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing an
4.3MEDIUM
CVE-2023-2624
< 3.2.1
The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading
6.1MEDIUM
CVE-2023-2623
< 3.2.1
The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, all
6.5MEDIUM
CVE-2022-0786
< 2.3.9
The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via th
9.8CRITICAL
threatengine.sh