Перейти к содержимому
Noroxi

Записи opensourcepos

19 опубликованных записей вендора opensourcepos.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
26,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

19 записей
  • CVE-2026-26746
    35Наблюдать

    OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    opensourcepos · open source point of sale20 февр. 2026 г.

  • CVE-2026-32888
    35Наблюдать

    Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale19 мар. 2026 г.

  • CVE-2025-68434
    35Наблюдать

    opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation

    ВысокаяCVSS 8,8Proof of conceptEPSS 0 %

    opensourcepos · open source point of sale17 дек. 2025 г.

  • CVE-2025-68147
    32Наблюдать

    opensourcepos has a Cross-site Scripting vulnerability

    ВысокаяCVSS 8,1Proof of conceptEPSS 0 %

    opensourcepos · open source point of sale17 дек. 2025 г.

  • CVE-2025-63800
    30Наблюдать

    The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale18 нояб. 2025 г.

  • CVE-2025-70093
    29Наблюдать

    An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.

    ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale13 февр. 2026 г.

  • CVE-2022-34578
    28Наблюдать

    Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    opensourcepos · open source point of sale28 июл. 2022 г.

  • CVE-2025-66921
    28Наблюдать

    A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to in

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    opensourcepos · open source point of sale17 дек. 2025 г.

  • CVE-2025-66923
    28Наблюдать

    A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    opensourcepos · open source point of sale17 дек. 2025 г.

  • CVE-2026-33730
    26Наблюдать

    Open Source Point of Sale has an IDOR in Password Change (Home)

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale26 мар. 2026 г.

  • CVE-2025-70094
    26Наблюдать

    A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitra

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale13 февр. 2026 г.

  • CVE-2025-70091
    26Наблюдать

    A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale13 февр. 2026 г.

  • CVE-2025-70095
    26Наблюдать

    A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exe

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale13 февр. 2026 г.

  • CVE-2025-66924
    24Наблюдать

    A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale17 дек. 2025 г.

  • CVE-2025-70092
    22Наблюдать

    A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale12 февр. 2026 г.

  • CVE-2026-26745
    21Наблюдать

    OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale20 февр. 2026 г.

  • CVE-2026-32712
    21Наблюдать

    Open Source Point of Sale has Stored XSS in Customer Name (Sales)

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale7 апр. 2026 г.

  • CVE-2026-39380
    21Наблюдать

    Open Source Point of Sale has Stored XSS in Stock Location (Configuration)

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale7 апр. 2026 г.

  • CVE-2025-68658
    19Наблюдать

    Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name field

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    opensourcepos · open source point of sale13 янв. 2026 г.