CVE-2025-66095SQL Injection in Design Kivicare

CWE-89SQL Injection3 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.0%
top 87.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 21

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

CVEListV5iqonic_design/kivicare3.6.13

🔴Vulnerability Details

2
CVEList
WordPress KiviCare plugin <= 3.6.13 - SQL Injection vulnerability2025-11-21
GHSA
GHSA-xrf2-cmw5-8q98: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-managemen2025-11-21
CVE-2025-66095 — SQL Injection in Design Kivicare | cvebase