Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Php Point Of Sale MEDIUM 6.1
CVE-2025-41011

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack o…

Mitigation only
Fix from $1,600 2026-04-21
Php Point Of Sale CRITICAL 9.8
CVE-2022-40293

The application was vulnerable to a session fixation that could be used hijack accounts.

No fix yet
Fix from $2,300 2022-10-31
Php Point Of Sale CRITICAL 9.8
CVE-2022-40296

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potential…

Mitigation only
Fix from $2,300 2022-10-31
Php Point Of Sale HIGH 8.8
CVE-2022-40294

The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data a…

Mitigation only
Fix from $1,950 2022-10-31
Php Point Of Sale MEDIUM 5.3
CVE-2022-40292

The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within…

Mitigation only
Fix from $1,600 2022-10-31
Php Point Of Sale CRITICAL 9.0
CVE-2022-40287

The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to…

Mitigation only
Fix from $2,300 2022-10-31
Php Point Of Sale CRITICAL 9.0
CVE-2022-40288

The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to esc…

Mitigation only
Fix from $2,300 2022-10-31
Php Point Of Sale CRITICAL 9.0
CVE-2022-40289

The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leverag…

Mitigation only
Fix from $2,300 2022-10-31
Php Point Of Sale HIGH 8.8
CVE-2022-40291

The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to …

Mitigation only
Fix from $1,950 2022-10-31
Php Point Of Sale MEDIUM 6.1
CVE-2022-40290

The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode generation functionality, allo…

Mitigation only
Fix from $1,600 2022-10-31
Php Point Of Sale MEDIUM 5.0
CVE-2011-3785

PHP Point Of Sale (POS) 10.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installat…

Mitigation only
Fix from $1,600 2011-09-24