Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

iqonicdesign — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting iqonicdesign. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Iqonicdesign operates primarily as a provider of WordPress themes and plugins, targeting web developers and designers seeking pre-built digital assets. This ecosystem has historically been associated with a significant volume of security flaws, currently totaling 25 recorded Common Vulnerabilities and Exposures (CVEs). The most prevalent vulnerability classes include Cross-Site Scripting (XSS), SQL Injection, and Remote Code Execution (RCE), often stemming from insufficient input validation and inadequate sanitization of user-supplied data. Additionally, issues related to broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate site functionalities or access sensitive administrative features. These deficiencies highlight systemic weaknesses in the codebase’s security architecture, particularly regarding how the software handles dynamic content and user interactions. The high number of CVEs suggests a pattern of recurring security oversights rather than isolated incidents, indicating a need for rigorous code auditing and stricter adherence to secure coding standards to mitigate risks for end-users relying on these components.

Found 7 results / 25Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-2991 KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token — KiviCare – Clinic & Patient Management System (EHR)CWE-287 7.3 High2026-03-18
CVE-2026-2992 KiviCare <= 4.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard — KiviCare – Clinic & Patient Management System (EHR)CWE-862 8.2 High2026-03-18
CVE-2026-0927 KiviCare – Clinic & Patient Management System (EHR) <= 3.6.15 - Missing Authorization to Unauthenticated Limited Arbitrary File Upload — KiviCare – Clinic & Patient Management System (EHR)CWE-862 5.3 Medium2026-01-23
CVE-2025-1572 KiviCare – Clinic & Patient Management System (EHR) <= 3.6.7 - Authenticated (Doctor+) SQL Injection via 'u_id' Parameter — KiviCare – Clinic & Patient Management System (EHR)CWE-89 6.5 Medium2025-02-28
CVE-2024-11729 KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Authenticated (Subscriber+) SQL Injection — KiviCare – Clinic & Patient Management System (EHR)CWE-89 6.5 Medium2024-12-06
CVE-2024-11730 KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Authenticated (Doctor/Receptionist+) SQL Injection — KiviCare – Clinic & Patient Management System (EHR)CWE-89 6.5 Medium2024-12-06
CVE-2024-11728 KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection — KiviCare – Clinic & Patient Management System (EHR)CWE-89 7.5 High2024-12-06

This page lists every published CVE security advisory associated with iqonicdesign. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.