Extension WordPress

Vulnérabilités KiviCare – Clinic & Patient Management System (EHR)

Cette page rassemble les failles publiées pour KiviCare – Clinic & Patient Management System (EHR), leurs plages de versions affectées et les correctifs signalés dans la base locale.

22Vulnérabilités
1Critiques
22Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de KiviCare – Clinic & Patient Management System (EHR)

22 fiches

CVE-2026-15072 Moyenne · 6,5
KiviCare – Clinic & Patient Management System (EHR)

KiviCare <= 4.5.0 – Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied…

Versions affectées

*-4.5.0

Correctif

4.5.1

Publication

10/07/2026

CVE-2026-15073 Moyenne · 6,5
KiviCare – Clinic & Patient Management System (EHR)

KiviCare <= 4.5.0 – Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied…

Versions affectées

*-4.5.0

Correctif

4.5.1

Publication

10/07/2026

CVE-2026-11990 Moyenne · 5,3
KiviCare – Clinic & Patient Management System (EHR)

KiviCare <= 4.4.0 – Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is…

Versions affectées

*-4.4.0

Correctif

4.5.0

Publication

09/07/2026

CVE-2026-42735 Moyenne · 5,3
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 4.3.0 – Missing Authorization

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.3.0. This makes it possible…

Versions affectées

*-4.3.0

Correctif

4.4.0

Publication

26/05/2026

CVE-2026-40792 Moyenne · 4,3
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 4.2.1 – Authenticated (Subscriber+) Insecure Direct Object Reference

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 due to missing validation on a user controlled key. This makes…

Versions affectées

*-4.2.1

Correctif

4.3.0

Publication

23/04/2026

CVE-2026-25034 Moyenne · 5,3
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.16 – Missing Authorization

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.6.16. This makes it possible…

Versions affectées

*-3.6.16

Correctif

4.0.0

Publication

23/03/2026

CVE-2026-25383 Moyenne · 6,1
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.16 – Reflected Cross-Site Scripting

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.6.16 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-3.6.16

Correctif

4.0.0

Publication

23/03/2026

CVE-2026-2991 Élevée · 7,3
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 – Unauthenticated Authentication Bypass via Social Login Token

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access…

Versions affectées

*-4.1.2

Correctif

4.1.3

Publication

17/03/2026

CVE-2026-2992 Élevée · 8,2
KiviCare – Clinic & Patient Management System (EHR)

KiviCare <= 4.1.2 – Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it…

Versions affectées

*-4.1.2

Correctif

4.1.3

Publication

17/03/2026

CVE-2026-0927 Moyenne · 5,3
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.15 – Missing Authorization to Unauthenticated Limited Arbitrary File Upload

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization checks in the uploadMedicalReport() function in all versions up to, and including, 3.6.15. This makes it…

Versions affectées

*-3.6.15

Correctif

3.6.16

Publication

22/01/2026

CVE-2025-1572 Moyenne · 6,5
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.7 – Authenticated (Doctor+) SQL Injection via 'u_id' Parameter

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up to, and including, 3.6.7 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-3.6.7

Correctif

3.6.8

Publication

27/02/2025

CVE-2024-11729 Moyenne · 6,5
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 – Authenticated (Subscriber+) SQL Injection

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' parameter of the get_widget_payment_options AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping…

Versions affectées

*-3.6.4

Correctif

3.6.5

Publication

05/12/2024

CVE-2024-11730 Moyenne · 6,5
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 – Authenticated (Doctor/Receptionist+) SQL Injection

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_data_list AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping…

Versions affectées

*-3.6.4

Correctif

3.6.5

Publication

05/12/2024

CVE-2024-11728 Élevée · 7,5
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 – Unauthenticated SQL Injection

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping…

Versions affectées

*-3.6.4

Correctif

3.6.5

Publication

05/12/2024

CVE-2023-2624 Moyenne · 6,1
KiviCare – Clinic & Patient Management System (EHR)

KiviCare <= 3.2.0 – Reflected Cross-Site Scripting via 'filterType'

The KiviCare plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'filterType' parameter in versions up to, and including, 3.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

[*, 3.2.1)

Correctif

3.2.1

Publication

05/06/2023

CVE-2023-2627 Moyenne · 5,4
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.2.0 – Missing Authorization

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to unauthorized access to and modification of data due to missing capability checks on multiple AJAX functions in versions up to, and including, 3.2.0.…

Versions affectées

*-3.2.0

Correctif

3.2.1

Publication

05/06/2023

CVE-2023-2628 Moyenne · 6,5
KiviCare – Clinic & Patient Management System (EHR)

KiviCare – Clinic & Patient Management System (EHR) <= 3.2.0 – Cross-Site Request Forgery

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.0. This is due to missing or incorrect nonce validation. This makes it possible…

Versions affectées

*-3.2.0

Correctif

3.2.1

Publication

05/06/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités