cbcvebase.

Iqonic Design Kivicare vulnerabilities

7 known vulnerabilities affecting iqonic_design/kivicare.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-66095P3HIGHCVSS 8.5≤ 3.6.132025-11-21
CVE-2025-66095 [HIGH] CWE-89 CVE-2025-66095: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13.
nvd
CVE-2026-25022P3HIGHCVSS 8.5≤ 3.6.162026-02-03
CVE-2026-25022 [HIGH] CWE-89 CVE-2026-25022: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.16.
nvd
CVE-2026-42735P3HIGHCVSS 8.2≤ 4.3.02026-05-27
CVE-2026-42735 [HIGH] CWE-288 CVE-2026-42735: Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kiv Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0.
nvd
CVE-2024-35659P3HIGHCVSS 8.8≤ 3.6.62024-06-08
CVE-2024-35659 [HIGH] CWE-862 CVE-2024-35659: Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allo Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6.
nvd
CVE-2026-25034P3MEDIUMCVSS 6.5≤ 3.6.162026-03-25
CVE-2026-25034 [MEDIUM] CWE-862 CVE-2026-25034: Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allo Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.16.
nvd
CVE-2026-40792P3MEDIUMCVSS 6.3≥ n/a, ≤ 4.2.12026-06-15
CVE-2026-40792 [MEDIUM] CWE-639 CVE-2026-40792: Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions. Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.
nvd
CVE-2026-25383P4HIGHCVSS 7.1≤ 3.6.162026-03-25
CVE-2026-25383 [HIGH] CWE-79 CVE-2026-25383: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects KiviCare: from n/a through <= 3.6.16.
nvd
Iqonic Design Kivicare vulnerabilities | cvebase