Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-6058EPSS 6% The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h… Wpbookit 1.0.5+ Fix from $2,3002025-07-12 HIGH 8.8 CVE-2025-6057 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function i… Wpbookit 1.0.5+ Fix from $1,9502025-07-12 CRITICAL 9.8 CVE-2025-3810 The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due… Wpbookit 1.0.3+ Fix from $2,3002025-05-09 CRITICAL 9.8 CVE-2025-3811 The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due… Wpbookit 1.0.3+ Fix from $2,3002025-05-09 MEDIUM 5.3 CVE-2025-32254 Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff… Wpbookit after 1.0.3 Fix from $1,6002025-04-04 MEDIUM 6.1 CVE-2025-26910 Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <=… Wpbookit 1.0.2+ Fix from $1,6002025-03-10 HIGH 8.8 CVE-2025-1572 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions … Kivicare 3.6.8+ Fix from $1,9502025-02-28 CRITICAL 9.8 CVE-2025-0357 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::ha… Wpbookit 1.6.10+ Fix from $2,3002025-01-25 CRITICAL 9.8 CVE-2024-10215 The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin … Wpbookit 1.6.6+ Fix from $2,3002025-01-09 CRITICAL 9.8 CVE-2024-54280 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Inje… Wpbookit after 1.6.0 Fix from $2,3002024-12-16 MEDIUM 6.5 CVE-2024-11730 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_… Kivicare 3.6.5+ Fix from $1,6002024-12-06 MEDIUM 6.5 CVE-2024-11729 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' par… Kivicare after 3.6.5 Fix from $1,6002024-12-06 HIGH 7.5 CVE-2024-11728EPSS 14% The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' paramete… Kivicare after 3.6.5 Fix from $1,9502024-12-06 HIGH 8.8 CVE-2024-35659 Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Contr… Kivicare after 3.6.4 Fix from $1,9502024-06-08 HIGH 8.8 CVE-2023-2628 The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow… Kivicare 3.2.1+ Fix from $1,9502023-06-27 MEDIUM 6.1 CVE-2023-2624 The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cro… Kivicare 3.2.1+ Fix from $1,6002023-06-27 MEDIUM 6.5 CVE-2023-2623 The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege… Kivicare 3.2.1+ Fix from $1,6002023-06-27 CRITICAL 9.8 CVE-2022-0786EPSS 13% The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX ac… Kivicare 2.3.9+ Fix from $2,3002022-06-13