Chikitsa's vulnerability profile concentrates in patient management software deployed in healthcare settings, a high-value but narrowly scoped attack surface centered on web-based clinical and administrative functions. The recurring weakness classes—cross-site scripting and unrestricted file uploads—reflect common input-handling and access-control gaps in web-facing healthcare applications where user-supplied data and document handling are central to workflow. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chikitsa over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-47758HIGH Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module uplo | Jan 15, 2026 | 8.8 | 31 | NO | NO |
CVE-2021-47757HIGH Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a | Jan 15, 2026 | 8.8 | 28 | NO | NO |
CVE-2021-42868MEDIUM A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointme | Mar 31, 2022 | 4.8 | 21 | NO | NO |
CVE-2021-38152MEDIUM index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS. | Aug 6, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-38149MEDIUM index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS. | Aug 6, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-42869MEDIUM A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appo | Mar 31, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-38151MEDIUM index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS. | Aug 6, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chikitsa.
Media articles that mention a CVE ID that affects a product developed by Chikitsa — matched by CVE ID, not by vendor name.