Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wpbookit CRITICAL 9.8
CVE-2025-6058EPSS 6%

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h…

Fix: 1.0.5+
Fix from $2,300 2025-07-12
Wpbookit HIGH 8.8
CVE-2025-6057

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_image_upload() function i…

Fix: 1.0.5+
Fix from $1,950 2025-07-12
Wpbookit CRITICAL 9.8
CVE-2025-3810

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due…

Fix: 1.0.3+
Fix from $2,300 2025-05-09
Wpbookit CRITICAL 9.8
CVE-2025-3811

The WPBookit plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.2. This is due…

Fix: 1.0.3+
Fix from $2,300 2025-05-09
Wpbookit MEDIUM 5.3
CVE-2025-32254

Missing Authorization vulnerability in Iqonic Design WPBookit wpbookit allows Accessing Functionality Not Properly Constrained by ACLs.This issue aff…

Fix: after 1.0.3
Fix from $1,600 2025-04-04
Wpbookit MEDIUM 6.1
CVE-2025-26910

Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <=…

Fix: 1.0.2+
Fix from $1,600 2025-03-10
Kivicare HIGH 8.8
CVE-2025-1572

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions …

Fix: 3.6.8+
Fix from $1,950 2025-02-28
Wpbookit CRITICAL 9.8
CVE-2025-0357

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPB_Profile_controller::ha…

Fix: 1.6.10+
Fix from $2,300 2025-01-25
Wpbookit CRITICAL 9.8
CVE-2024-10215

The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin …

Fix: 1.6.6+
Fix from $2,300 2025-01-09
Wpbookit CRITICAL 9.8
CVE-2024-54280

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit wpbookit allows SQL Inje…

Fix: after 1.6.0
Fix from $2,300 2024-12-16
Kivicare MEDIUM 6.5
CVE-2024-11730

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_…

Fix: 3.6.5+
Fix from $1,600 2024-12-06
Kivicare MEDIUM 6.5
CVE-2024-11729

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' par…

Fix: after 3.6.5
Fix from $1,600 2024-12-06
Kivicare HIGH 7.5
CVE-2024-11728EPSS 14%

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' paramete…

Fix: after 3.6.5
Fix from $1,950 2024-12-06
Kivicare HIGH 8.8
CVE-2024-35659

Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Contr…

Fix: after 3.6.4
Fix from $1,950 2024-06-08
Kivicare HIGH 8.8
CVE-2023-2628

The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow…

Fix: 3.2.1+
Fix from $1,950 2023-06-27
Kivicare MEDIUM 6.1
CVE-2023-2624

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cro…

Fix: 3.2.1+
Fix from $1,600 2023-06-27
Kivicare MEDIUM 6.5
CVE-2023-2623

The KiviCare WordPress plugin before 3.2.1 does not restrict the information returned in a response and returns all user data, allowing low privilege…

Fix: 3.2.1+
Fix from $1,600 2023-06-27
Kivicare CRITICAL 9.8
CVE-2022-0786EPSS 13%

The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX ac…

Fix: 2.3.9+
Fix from $2,300 2022-06-13