Known Vulnerabilities for KiviCare by Iqonic Design
Listed below are 10 of the newest known vulnerabilities associated with "KiviCare" by "Iqonic Design".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40792 json | Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions. | Not Provided | 2026-06-15 | 2026-06-15 |
| CVE-2026-19417 json | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being serv... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-19416 json | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, all... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-15453 json | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the... | Not Provided | 2026-08-15 | 2026-08-17 |
| CVE-2026-15073 json | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the... | Not Provided | 2026-07-11 | 2026-07-15 |
| CVE-2026-15072 json | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-13613 json | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them ... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-13612 json | The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowin... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-13611 json | The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unau... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-13610 json | The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration e... | Not Provided | 2026-08-13 | 2026-08-14 |