Reflected XSS Vulnerability in KiviCare Clinic Management System by Iqonic Design
CVE-2026-25383
7.1HIGH
What is CVE-2026-25383?
The KiviCare Clinic Management System by Iqonic Design is susceptible to a reflected XSS vulnerability that allows attackers to inject malicious scripts into web pages viewed by users. This vulnerability can be exploited to steal sensitive information or perform unauthorized actions within a user's session. Affected versions include KiviCare prior to 3.6.16, making it imperative for users to update their installations to mitigate potential risks associated with this security flaw.
Affected Version(s)
KiviCare 0 <= 3.6.16