Known Vulnerabilities for Clinic by VSee
Listed below are 2 of the newest known vulnerabilities associated with "Clinic" by "VSee".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-52868 json | An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In ... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-42735 json | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-s... | Not Provided | 2026-05-27 | 2026-05-27 |
| CVE-2026-15453 json | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the... | Not Provided | 2026-08-15 | 2026-08-17 |
| CVE-2026-15073 json | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the... | Not Provided | 2026-07-11 | 2026-07-15 |
| CVE-2026-15072 json | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the... | Not Provided | 2026-07-11 | 2026-07-13 |
| CVE-2026-13613 json | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them ... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-13610 json | The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration e... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-13381 json | VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files ... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-13380 json | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticate... | Not Provided | 2026-07-20 | 2026-07-21 |
| CVE-2026-11990 json | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all v... | Not Provided | 2026-07-10 | 2026-07-10 |