Extension WordPress
Vulnérabilités KiviCare – Clinic & Patient Management System (EHR)
Cette page rassemble les failles publiées pour KiviCare – Clinic & Patient Management System (EHR), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de KiviCare – Clinic & Patient Management System (EHR)
22 fiches
KiviCare <= 4.5.0 – Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied…
*-4.5.0
4.5.1
10/07/2026
KiviCare <= 4.5.0 – Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied…
*-4.5.0
4.5.1
10/07/2026
KiviCare <= 4.4.0 – Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is…
*-4.4.0
4.5.0
09/07/2026
KiviCare – Clinic & Patient Management System (EHR) <= 4.3.0 – Missing Authorization
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.3.0. This makes it possible…
*-4.3.0
4.4.0
26/05/2026
KiviCare – Clinic & Patient Management System (EHR) <= 4.2.1 – Authenticated (Subscriber+) Insecure Direct Object Reference
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 due to missing validation on a user controlled key. This makes…
*-4.2.1
4.3.0
23/04/2026
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.16 – Missing Authorization
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.6.16. This makes it possible…
*-3.6.16
4.0.0
23/03/2026
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.16 – Reflected Cross-Site Scripting
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.16 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.6.16
4.0.0
23/03/2026
KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 – Unauthenticated Authentication Bypass via Social Login Token
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access…
*-4.1.2
4.1.3
17/03/2026
KiviCare <= 4.1.2 – Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it…
*-4.1.2
4.1.3
17/03/2026
KiviCare <= 3.6.16 – Authenticated (Receptionist+) SQL Injection
The KiviCare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-3.6.16
4.0.0
01/02/2026
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.15 – Missing Authorization to Unauthenticated Limited Arbitrary File Upload
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization checks in the uploadMedicalReport() function in all versions up to, and including, 3.6.15. This makes it…
*-3.6.15
3.6.16
22/01/2026
KiviCare <= 3.6.13 – Authenticated (Patient+) SQL Injection
The KiviCare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-3.6.13
3.6.14
27/11/2025
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.7 – Authenticated (Doctor+) SQL Injection via 'u_id' Parameter
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up to, and including, 3.6.7 due to insufficient escaping on the user supplied parameter…
*-3.6.7
3.6.8
27/02/2025
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 – Authenticated (Subscriber+) SQL Injection
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' parameter of the get_widget_payment_options AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping…
*-3.6.4
3.6.5
05/12/2024
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 – Authenticated (Doctor/Receptionist+) SQL Injection
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_data_list AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping…
*-3.6.4
3.6.5
05/12/2024
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 – Unauthenticated SQL Injection
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping…
*-3.6.4
3.6.5
05/12/2024
KiviCare <= 3.6.6 – Authenticated (Patient+) Insecure Direct Object Reference
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.6.6 due to missing validation on a user controlled key. This makes…
*-3.6.6
3.6.7
03/06/2024
KiviCare <= 3.2.0 – Reflected Cross-Site Scripting via 'filterType'
The KiviCare plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filterType' parameter in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
[*, 3.2.1)
3.2.1
05/06/2023
KiviCare – Clinic & Patient Management System (EHR) <= 3.2.0 – Missing Authorization
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access to and modification of data due to missing capability checks on multiple AJAX functions in versions up to, and including, 3.2.0.…
*-3.2.0
3.2.1
05/06/2023
KiviCare – Clinic & Patient Management System (EHR) <= 3.2.0 – Cross-Site Request Forgery
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation. This makes it possible…
*-3.2.0
3.2.1
05/06/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.