Remoteclinic maintains a focused telemedicine and remote-consultation platform that, despite its narrow product scope, ranks among the more prominent vendors in the vulnerability landscape. Vulnerabilities affecting the product skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrated around application-layer input-handling and access-control weaknesses including cross-site scripting, SQL injection, improper access control, unsafe file uploads, and exposure of sensitive information. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Remoteclinic over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9775CRITICAL A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.php. The manipulation of the argument image results in unres | Sep 1, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9772CRITICAL A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Performing manipulation of the argument image results in unrestric | Sep 1, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-48152CRITICAL SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive information via the id parameter to /medicines/profile.php. | Jan 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-30044MEDIUM Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php. | Apr 13, 2021 | 5.4 | 29 | NO | YES |
CVE-2021-30039MEDIUM Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php. | Apr 13, 2021 | 5.4 | 29 | NO | YES |
CVE-2021-30042MEDIUM Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register.php | Apr 13, 2021 | 5.4 | 28 | NO | YES |
CVE-2021-30034MEDIUM Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php. | Apr 13, 2021 | 5.4 | 28 | NO | YES |
CVE-2021-30030MEDIUM Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php. | Apr 13, 2021 | 5.4 | 28 | NO | YES |
CVE-2021-31329MEDIUM Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php | Apr 21, 2021 | 5.4 | 27 | NO | YES |
CVE-2021-31327MEDIUM Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field. | Apr 21, 2021 | 5.4 | 27 | NO | YES |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Remoteclinic.
Media articles that mention a CVE ID that affects a product developed by Remoteclinic — matched by CVE ID, not by vendor name.