Skip to content
Noroxi

opensourcepos records

19 published records for vendor opensourcepos.

All records

19 records
  • OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.

    HighCVSS 8.8Proof of conceptEPSS 1%

    opensourcepos · open source point of saleFeb 20, 2026

  • Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality

    HighCVSS 8.8No exploitEPSS 0%

    opensourcepos · open source point of saleMar 19, 2026

  • opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation

    HighCVSS 8.8Proof of conceptEPSS 0%

    opensourcepos · open source point of saleDec 17, 2025

  • opensourcepos has a Cross-site Scripting vulnerability

    HighCVSS 8.1Proof of conceptEPSS 0%

    opensourcepos · open source point of saleDec 17, 2025

  • The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing

    HighCVSS 7.5No exploitEPSS 0%

    opensourcepos · open source point of saleNov 18, 2025

  • An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.

    HighCVSS 7.4No exploitEPSS 0%

    opensourcepos · open source point of saleFeb 13, 2026

  • Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

    HighCVSS 7.2No exploitEPSS 1%

    opensourcepos · open source point of saleJul 28, 2022

  • A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to in

    HighCVSS 7.2No exploitEPSS 1%

    opensourcepos · open source point of saleDec 17, 2025

  • A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec

    HighCVSS 7.2No exploitEPSS 1%

    opensourcepos · open source point of saleDec 17, 2025

  • Open Source Point of Sale has an IDOR in Password Change (Home)

    MediumCVSS 6.5No exploitEPSS 0%

    opensourcepos · open source point of saleMar 26, 2026

  • A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitra

    MediumCVSS 6.5No exploitEPSS 0%

    opensourcepos · open source point of saleFeb 13, 2026

  • A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip

    MediumCVSS 6.5No exploitEPSS 0%

    opensourcepos · open source point of saleFeb 13, 2026

  • A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exe

    MediumCVSS 6.5No exploitEPSS 0%

    opensourcepos · open source point of saleFeb 13, 2026

  • A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec

    MediumCVSS 6.1No exploitEPSS 0%

    opensourcepos · open source point of saleDec 17, 2025

  • A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip

    MediumCVSS 5.5No exploitEPSS 0%

    opensourcepos · open source point of saleFeb 12, 2026

  • OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.

    MediumCVSS 5.3No exploitEPSS 0%

    opensourcepos · open source point of saleFeb 20, 2026

  • Open Source Point of Sale has Stored XSS in Customer Name (Sales)

    MediumCVSS 5.4No exploitEPSS 0%

    opensourcepos · open source point of saleApr 7, 2026

  • Open Source Point of Sale has Stored XSS in Stock Location (Configuration)

    MediumCVSS 5.4No exploitEPSS 0%

    opensourcepos · open source point of saleApr 7, 2026

  • Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name field

    MediumCVSS 4.8No exploitEPSS 0%

    opensourcepos · open source point of saleJan 13, 2026