Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-32712 Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Sc… Open Source Point Of Sale 3.4.3+ Fix from $1,6002026-04-07 MEDIUM 5.4 CVE-2026-39380 Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Sc… Open Source Point Of Sale 3.4.3+ Fix from $1,6002026-04-07 MEDIUM 6.5 CVE-2026-33730 Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2… Open Source Point Of Sale 3.4.2+ Fix from $1,6002026-03-27 HIGH 8.8 CVE-2026-32888 Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in t… Open Source Point Of Sale after 3.4.2 Fix from $1,9502026-03-20 HIGH 8.8 CVE-2026-26746 OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files… Open Source Point Of Sale No fix yet Fix from $1,9502026-02-20 MEDIUM 5.3 CVE-2026-26745 OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is … Open Source Point Of Sale No fix yet Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2025-70095 A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbi… Open Source Point Of Sale No fix yet Fix from $1,6002026-02-13 HIGH 7.4 CVE-2025-70093 An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response. Open Source Point Of Sale Patch available Fix from $1,9502026-02-13 MEDIUM 6.5 CVE-2025-70091 A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTM… Open Source Point Of Sale No fix yet Fix from $1,6002026-02-13 MEDIUM 6.5 CVE-2025-70094 A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web sc… Open Source Point Of Sale Patch available Fix from $1,6002026-02-13 MEDIUM 5.5 CVE-2025-70092 A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTM… Open Source Point Of Sale No fix yet Fix from $1,6002026-02-12 HIGH 8.8 CVE-2025-68434 Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.… Open Source Point Of Sale 3.4.2+ Fix from $1,9502025-12-17 HIGH 8.1 CVE-2025-68147 Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.… Open Source Point Of Sale 3.4.2+ Fix from $1,9502025-12-17 MEDIUM 6.1 CVE-2025-66924 A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitra… Open Source Point Of Sale No fix yet Fix from $1,6002025-12-17 HIGH 7.2 CVE-2025-66923 A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitra… Open Source Point Of Sale No fix yet Fix from $1,9502025-12-17 HIGH 7.2 CVE-2025-66921 A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbi… Open Source Point Of Sale No fix yet Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-63800 The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-s… Open Source Point Of Sale No fix yet Fix from $1,9502025-11-18 HIGH 7.2 CVE-2022-34578 Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. Open Source Point Of Sale No fix yet Fix from $1,9502022-07-28