Iqonic Design Kivicare vulnerabilities
5 known vulnerabilities affecting iqonic_design/kivicare.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-25383HIGHCVSS 7.1≥ n/a, ≤ <= 3.6.162026-03-25
CVE-2026-25383 [HIGH] CWE-79 CVE-2026-25383: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects KiviCare: from n/a through <= 3.6.16.
cvelistv5nvd
CVE-2026-25034MEDIUMCVSS 6.5≥ n/a, ≤ <= 3.6.162026-03-25
CVE-2026-25034 [MEDIUM] CWE-862 CVE-2026-25034: Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allo
Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.16.
cvelistv5nvd
CVE-2026-25022HIGHCVSS 8.5≤ 3.6.162026-02-03
CVE-2026-25022 [HIGH] CWE-89 CVE-2026-25022: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.16.
cvelistv5nvd
CVE-2025-66095MEDIUMCVSS 4.3≤ 3.6.132025-11-21
CVE-2025-66095 [MEDIUM] CWE-89 CVE-2025-66095: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13.
cvelistv5nvd
CVE-2024-35659HIGHCVSS 8.8≤ 3.6.62024-06-08
CVE-2024-35659 [HIGH] CWE-862 CVE-2024-35659: Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allo
Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6.
cvelistv5nvd