SecAlerts
kivicare logo

kivicare

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 6, 2024 to present

10
Total CVEs
3
Critical+High
1
Exploited
1
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
40/100
medium
⚠️ 1 Active Exploits🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
0
High
3
Medium
6
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
7

Most Affected Products

1. Iqonic Kivicare Wordpress4
2. KiviCare KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress2
3. KiviCare Clinic & Patient Management System2
4. KiviCare WordPress plugin1
5. KiviCare Clinic & Patient Management System (EHR) plugin for WordPress1

Recent Vulnerabilities

See more →
CVE-2026-13613
unknown

KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint

8/12/2026🔧 No Patch
CVE-2026-15072
CVSS 6.5medium

KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder

7/11/2026🔧 No Patch
CVE-2026-15073
CVSS 6.5medium

KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController

7/11/2026🔧 No Patch
CVE-2026-11990
CVSS 5.3medium

KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint

7/10/2026🔧 No Patch
CVE-2026-2991
CVSS 7.3high

KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token

3/18/2026🔧 No Patch
CVE-2026-0927
CVSS 5.3EPSS 0%medium

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.15 - Missing Authorization to Unauthenticated Limited Arbitrary File Upload

1/23/2026🔧 No Patch
CVE-2025-1572
CVSS 8.8high

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.7 - Authenticated (Doctor+) SQL Injection via 'u_id' Parameter

2/28/2025
CVE-2024-11729
CVSS 6.5medium

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Authenticated (Subscriber+) SQL Injection

12/6/2024
CVE-2024-11730
CVSS 6.5medium

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Authenticated (Doctor/Receptionist+) SQL Injection

12/6/2024
CVE-2024-11728
CVSS 7.5high

KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection

12/6/2024⚠ Exploited

Monitor kivicare in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.