Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-26746 OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files… Open Source Point Of Sale No fix yet Fix from $1,9502026-02-20 MEDIUM 5.3 CVE-2026-26745 OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is … Open Source Point Of Sale No fix yet Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2025-70095 A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbi… Open Source Point Of Sale No fix yet Fix from $1,6002026-02-13 MEDIUM 6.5 CVE-2025-70091 A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTM… Open Source Point Of Sale No fix yet Fix from $1,6002026-02-13 MEDIUM 5.5 CVE-2025-70092 A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTM… Open Source Point Of Sale No fix yet Fix from $1,6002026-02-12 MEDIUM 6.1 CVE-2025-66924 A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitra… Open Source Point Of Sale No fix yet Fix from $1,6002025-12-17 HIGH 7.2 CVE-2025-66923 A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitra… Open Source Point Of Sale No fix yet Fix from $1,9502025-12-17 HIGH 7.2 CVE-2025-66921 A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbi… Open Source Point Of Sale No fix yet Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-63800 The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-s… Open Source Point Of Sale No fix yet Fix from $1,9502025-11-18 HIGH 7.2 CVE-2022-34578 Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. Open Source Point Of Sale No fix yet Fix from $1,9502022-07-28