Iqonic
Iqonic Kivicare: vulnerabilidades y CVE
Iqonic Kivicare tiene 29 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses19
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13611 | Media (5.3) | 0.19% | — | 1 sept 2026 | The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is… |
| CVE-2026-19417 | Media (6.5) | 0.34% | — | 19 ago 2026 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library,… |
| CVE-2026-19416 | Media (4.3) | 0.27% | — | 19 ago 2026 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments. |
| CVE-2026-15453 | Media (6.5) | 0.41% | — | 15 ago 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping… |
| CVE-2026-13610 | Alta (7.5) | 0.41% | — | 13 ago 2026 | The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff… |
| CVE-2026-13613 | Alta (8.8) | 0.43% | — | 12 ago 2026 | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL… |
| CVE-2026-13612 | Media (4.3) | 0.25% | — | 12 ago 2026 | The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other patients' bills, invoices and appointment… |
| CVE-2026-15073 | Media (6.5) | 0.41% | — | 11 jul 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on… |
| CVE-2026-15072 | Media (6.5) | 0.47% | — | 11 jul 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on… |
| CVE-2026-11990 | Media (5.3) | 0.56% | — | 10 jul 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a… |
| CVE-2026-40792 | Media (6.3) | 0.26% | — | 15 jun 2026 | Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions. |
| CVE-2026-42735 | Alta (8.2) | 0.44% | — | 27 may 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <=… |
| CVE-2026-25383 | Alta (7.1) | 0.18% | — | 25 mar 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects KiviCare: from n/a… |
| CVE-2026-25034 | Media (6.5) | 0.19% | — | 25 mar 2026 | Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <=… |
| CVE-2026-2992 | Alta (8.2) | 0.42% | — | 18 mar 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all… |
| CVE-2026-2991 | Alta (7.3) | 0.54% | — | 18 mar 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not… |
| CVE-2026-25022 | Alta (8.5) | 0.24% | — | 3 feb 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from… |
| CVE-2026-0927 | Media (5.3) | 0.33% | — | 23 ene 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization checks in the uploadMedicalReport() function in all versions up to, and… |
| CVE-2025-66095 | Alta (8.5) | 0.24% | — | 21 nov 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a… |
| CVE-2025-1572 | Alta (8.8) | 0.53% | — | 28 feb 2025 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up to, and including, 3.6.7 due to insufficient escaping on the user… |
| CVE-2024-11730 | Media (6.5) | 0.41% | — | 6 dic 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_data_list AJAX action in all versions up to, and including, 3.6.4 due… |
| CVE-2024-11729 | Media (6.5) | 0.58% | — | 6 dic 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' parameter of the get_widget_payment_options AJAX action in all versions… |
| CVE-2024-11728 | Alta (7.5) | 14% | — | 6 dic 2024 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and… |
| CVE-2024-35659 | Alta (8.8) | 0.34% | — | 8 jun 2024 | Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <=… |
| CVE-2023-2628 | Alta (8.8) | 0.39% | — | 27 jun 2023 | The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF… |
| CVE-2023-2627 | Media (4.3) | 0.25% | — | 27 jun 2023 | The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not… |
| CVE-2023-2624 | Media (6.1) | 1.2% | — | 27 jun 2023 | The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users… |
| CVE-2023-2623 | Media (6.5) | 0.75% | — | 27 jun 2023 | The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege users such as subscriber to retrieve sensitive information such as… |
| CVE-2022-0786 | Crítica (9.8) | 13% | — | 13 jun 2022 | The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.