opensourcepos records
19 published records for vendor opensourcepos.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 26.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-20 Improper Input Validation2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2026-26746Proof of concept | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.opensourcepos · open source point of sale · CWE-434 | High8.8 | — | 0.8% | Feb 20, 2026 |
35Monitor | CVE-2026-32888No exploit | Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionalityopensourcepos · open source point of sale · CWE-89 | High8.8 | — | 0.5% | Mar 19, 2026 |
35Monitor | CVE-2025-68434Proof of concept | opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creationopensourcepos · open source point of sale · CWE-352 | High8.8 | — | 0.3% | Dec 17, 2025 |
32Monitor | CVE-2025-68147Proof of concept | opensourcepos has a Cross-site Scripting vulnerabilityopensourcepos · open source point of sale · CWE-79 | High8.1 | — | 0.4% | Dec 17, 2025 |
30Monitor | CVE-2025-63800No exploit | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missingopensourcepos · open source point of sale · CWE-521 | High7.5 | — | 0.5% | Nov 18, 2025 |
29Monitor | CVE-2025-70093No exploit | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.opensourcepos · open source point of sale · CWE-77 | High7.4 | — | 0.4% | Feb 13, 2026 |
28Monitor | CVE-2022-34578No exploit | Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.opensourcepos · open source point of sale · CWE-434 | High7.2 | — | 1.2% | Jul 28, 2022 |
28Monitor | CVE-2025-66921No exploit | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inopensourcepos · open source point of sale · CWE-20 | High7.2 | — | 0.6% | Dec 17, 2025 |
28Monitor | CVE-2025-66923No exploit | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injecopensourcepos · open source point of sale · CWE-20 | High7.2 | — | 0.6% | Dec 17, 2025 |
26Monitor | CVE-2026-33730No exploit | Open Source Point of Sale has an IDOR in Password Change (Home)opensourcepos · open source point of sale · CWE-639 | Medium6.5 | — | 0.4% | Mar 26, 2026 |
26Monitor | CVE-2025-70094No exploit | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitraopensourcepos · open source point of sale · CWE-79 | Medium6.5 | — | 0.2% | Feb 13, 2026 |
26Monitor | CVE-2025-70091No exploit | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripopensourcepos · open source point of sale · CWE-79 | Medium6.5 | — | 0.2% | Feb 13, 2026 |
26Monitor | CVE-2025-70095No exploit | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exeopensourcepos · open source point of sale · CWE-79 | Medium6.5 | — | 0.2% | Feb 13, 2026 |
24Monitor | CVE-2025-66924No exploit | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injecopensourcepos · open source point of sale · CWE-79 | Medium6.1 | — | 0.3% | Dec 17, 2025 |
22Monitor | CVE-2025-70092No exploit | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripopensourcepos · open source point of sale · CWE-79 | Medium5.5 | — | 0.2% | Feb 12, 2026 |
21Monitor | CVE-2026-26745No exploit | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.opensourcepos · open source point of sale · CWE-89 | Medium5.3 | — | 0.4% | Feb 20, 2026 |
21Monitor | CVE-2026-32712No exploit | Open Source Point of Sale has Stored XSS in Customer Name (Sales)opensourcepos · open source point of sale · CWE-79 | Medium5.4 | — | 0.2% | Apr 7, 2026 |
21Monitor | CVE-2026-39380No exploit | Open Source Point of Sale has Stored XSS in Stock Location (Configuration)opensourcepos · open source point of sale · CWE-79 | Medium5.4 | — | 0.2% | Apr 7, 2026 |
19Monitor | CVE-2025-68658No exploit | Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name fieldopensourcepos · open source point of sale · CWE-79 | Medium4.8 | — | 0.2% | Jan 13, 2026 |
- CVE-2026-2674635Monitor
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.
HighCVSS 8.8Proof of conceptEPSS 1%opensourcepos · open source point of saleFeb 20, 2026
- CVE-2026-3288835Monitor
Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality
HighCVSS 8.8No exploitEPSS 0%opensourcepos · open source point of saleMar 19, 2026
- CVE-2025-6843435Monitor
opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation
HighCVSS 8.8Proof of conceptEPSS 0%opensourcepos · open source point of saleDec 17, 2025
- CVE-2025-6814732Monitor
opensourcepos has a Cross-site Scripting vulnerability
HighCVSS 8.1Proof of conceptEPSS 0%opensourcepos · open source point of saleDec 17, 2025
- CVE-2025-6380030Monitor
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing
HighCVSS 7.5No exploitEPSS 0%opensourcepos · open source point of saleNov 18, 2025
- CVE-2025-7009329Monitor
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
HighCVSS 7.4No exploitEPSS 0%opensourcepos · open source point of saleFeb 13, 2026
- CVE-2022-3457828Monitor
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
HighCVSS 7.2No exploitEPSS 1%opensourcepos · open source point of saleJul 28, 2022
- CVE-2025-6692128Monitor
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to in
HighCVSS 7.2No exploitEPSS 1%opensourcepos · open source point of saleDec 17, 2025
- CVE-2025-6692328Monitor
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec
HighCVSS 7.2No exploitEPSS 1%opensourcepos · open source point of saleDec 17, 2025
- CVE-2026-3373026Monitor
Open Source Point of Sale has an IDOR in Password Change (Home)
MediumCVSS 6.5No exploitEPSS 0%opensourcepos · open source point of saleMar 26, 2026
- CVE-2025-7009426Monitor
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitra
MediumCVSS 6.5No exploitEPSS 0%opensourcepos · open source point of saleFeb 13, 2026
- CVE-2025-7009126Monitor
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip
MediumCVSS 6.5No exploitEPSS 0%opensourcepos · open source point of saleFeb 13, 2026
- CVE-2025-7009526Monitor
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exe
MediumCVSS 6.5No exploitEPSS 0%opensourcepos · open source point of saleFeb 13, 2026
- CVE-2025-6692424Monitor
A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec
MediumCVSS 6.1No exploitEPSS 0%opensourcepos · open source point of saleDec 17, 2025
- CVE-2025-7009222Monitor
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip
MediumCVSS 5.5No exploitEPSS 0%opensourcepos · open source point of saleFeb 12, 2026
- CVE-2026-2674521Monitor
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.
MediumCVSS 5.3No exploitEPSS 0%opensourcepos · open source point of saleFeb 20, 2026
- CVE-2026-3271221Monitor
Open Source Point of Sale has Stored XSS in Customer Name (Sales)
MediumCVSS 5.4No exploitEPSS 0%opensourcepos · open source point of saleApr 7, 2026
- CVE-2026-3938021Monitor
Open Source Point of Sale has Stored XSS in Stock Location (Configuration)
MediumCVSS 5.4No exploitEPSS 0%opensourcepos · open source point of saleApr 7, 2026
- CVE-2025-6865819Monitor
Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name field
MediumCVSS 4.8No exploitEPSS 0%opensourcepos · open source point of saleJan 13, 2026