KiviCare – Clinic & Patient Management System (EHR) <= 4.2.1 - Authenticated (Subscriber+) Insecure Direct Object Reference
KiviCare – Clinic & Patient Management System (EHR)
Minimum safe version
4.3.0
Update to 4.3.0 or later to address 18 fixable vulnerabilities
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.15 - Missing Authorization to Unauthenticated Limited Arbitrary File Upload
KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token
KiviCare <= 4.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard
CVE-2026-25383
CVE-2026-25034
CVE-2026-25022
KiviCare <= 3.6.13 - Authenticated (Patient+) SQL Injection
KiviCare – Clinic & Patient Management System (EHR) <= 3.6.7 - Authenticated (Doctor+) SQL Injection via 'u_id' Parameter
CVE-2024-11728
CVE-2024-11730
CVE-2024-11729
CVE-2024-35659
CVE-2023-2627
CVE-2023-2624
CVE-2023-2623
CVE-2023-2628
CVE-2022-0786