Записи opensourcepos
19 опубликованных записей вендора opensourcepos.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 26,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-20 Improper Input Validation2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2026-26746Proof of concept | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.opensourcepos · open source point of sale · CWE-434 | Высокая8,8 | — | 0,8 % | 20 февр. 2026 г. |
35Наблюдать | CVE-2026-32888Эксплойта нет | Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionalityopensourcepos · open source point of sale · CWE-89 | Высокая8,8 | — | 0,5 % | 19 мар. 2026 г. |
35Наблюдать | CVE-2025-68434Proof of concept | opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creationopensourcepos · open source point of sale · CWE-352 | Высокая8,8 | — | 0,3 % | 17 дек. 2025 г. |
32Наблюдать | CVE-2025-68147Proof of concept | opensourcepos has a Cross-site Scripting vulnerabilityopensourcepos · open source point of sale · CWE-79 | Высокая8,1 | — | 0,4 % | 17 дек. 2025 г. |
30Наблюдать | CVE-2025-63800Эксплойта нет | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missingopensourcepos · open source point of sale · CWE-521 | Высокая7,5 | — | 0,5 % | 18 нояб. 2025 г. |
29Наблюдать | CVE-2025-70093Эксплойта нет | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.opensourcepos · open source point of sale · CWE-77 | Высокая7,4 | — | 0,4 % | 13 февр. 2026 г. |
28Наблюдать | CVE-2022-34578Эксплойта нет | Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.opensourcepos · open source point of sale · CWE-434 | Высокая7,2 | — | 1,2 % | 28 июл. 2022 г. |
28Наблюдать | CVE-2025-66921Эксплойта нет | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inopensourcepos · open source point of sale · CWE-20 | Высокая7,2 | — | 0,6 % | 17 дек. 2025 г. |
28Наблюдать | CVE-2025-66923Эксплойта нет | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injecopensourcepos · open source point of sale · CWE-20 | Высокая7,2 | — | 0,6 % | 17 дек. 2025 г. |
26Наблюдать | CVE-2026-33730Эксплойта нет | Open Source Point of Sale has an IDOR in Password Change (Home)opensourcepos · open source point of sale · CWE-639 | Средняя6,5 | — | 0,4 % | 26 мар. 2026 г. |
26Наблюдать | CVE-2025-70094Эксплойта нет | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitraopensourcepos · open source point of sale · CWE-79 | Средняя6,5 | — | 0,2 % | 13 февр. 2026 г. |
26Наблюдать | CVE-2025-70091Эксплойта нет | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripopensourcepos · open source point of sale · CWE-79 | Средняя6,5 | — | 0,2 % | 13 февр. 2026 г. |
26Наблюдать | CVE-2025-70095Эксплойта нет | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exeopensourcepos · open source point of sale · CWE-79 | Средняя6,5 | — | 0,2 % | 13 февр. 2026 г. |
24Наблюдать | CVE-2025-66924Эксплойта нет | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injecopensourcepos · open source point of sale · CWE-79 | Средняя6,1 | — | 0,3 % | 17 дек. 2025 г. |
22Наблюдать | CVE-2025-70092Эксплойта нет | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripopensourcepos · open source point of sale · CWE-79 | Средняя5,5 | — | 0,2 % | 12 февр. 2026 г. |
21Наблюдать | CVE-2026-26745Эксплойта нет | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.opensourcepos · open source point of sale · CWE-89 | Средняя5,3 | — | 0,4 % | 20 февр. 2026 г. |
21Наблюдать | CVE-2026-32712Эксплойта нет | Open Source Point of Sale has Stored XSS in Customer Name (Sales)opensourcepos · open source point of sale · CWE-79 | Средняя5,4 | — | 0,2 % | 7 апр. 2026 г. |
21Наблюдать | CVE-2026-39380Эксплойта нет | Open Source Point of Sale has Stored XSS in Stock Location (Configuration)opensourcepos · open source point of sale · CWE-79 | Средняя5,4 | — | 0,2 % | 7 апр. 2026 г. |
19Наблюдать | CVE-2025-68658Эксплойта нет | Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name fieldopensourcepos · open source point of sale · CWE-79 | Средняя4,8 | — | 0,2 % | 13 янв. 2026 г. |
- CVE-2026-2674635Наблюдать
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %opensourcepos · open source point of sale20 февр. 2026 г.
- CVE-2026-3288835Наблюдать
Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %opensourcepos · open source point of sale19 мар. 2026 г.
- CVE-2025-6843435Наблюдать
opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation
ВысокаяCVSS 8,8Proof of conceptEPSS 0 %opensourcepos · open source point of sale17 дек. 2025 г.
- CVE-2025-6814732Наблюдать
opensourcepos has a Cross-site Scripting vulnerability
ВысокаяCVSS 8,1Proof of conceptEPSS 0 %opensourcepos · open source point of sale17 дек. 2025 г.
- CVE-2025-6380030Наблюдать
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %opensourcepos · open source point of sale18 нояб. 2025 г.
- CVE-2025-7009329Наблюдать
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %opensourcepos · open source point of sale13 февр. 2026 г.
- CVE-2022-3457828Наблюдать
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %opensourcepos · open source point of sale28 июл. 2022 г.
- CVE-2025-6692128Наблюдать
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to in
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %opensourcepos · open source point of sale17 дек. 2025 г.
- CVE-2025-6692328Наблюдать
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %opensourcepos · open source point of sale17 дек. 2025 г.
- CVE-2026-3373026Наблюдать
Open Source Point of Sale has an IDOR in Password Change (Home)
СредняяCVSS 6,5Эксплойта нетEPSS 0 %opensourcepos · open source point of sale26 мар. 2026 г.
- CVE-2025-7009426Наблюдать
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitra
СредняяCVSS 6,5Эксплойта нетEPSS 0 %opensourcepos · open source point of sale13 февр. 2026 г.
- CVE-2025-7009126Наблюдать
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip
СредняяCVSS 6,5Эксплойта нетEPSS 0 %opensourcepos · open source point of sale13 февр. 2026 г.
- CVE-2025-7009526Наблюдать
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exe
СредняяCVSS 6,5Эксплойта нетEPSS 0 %opensourcepos · open source point of sale13 февр. 2026 г.
- CVE-2025-6692424Наблюдать
A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec
СредняяCVSS 6,1Эксплойта нетEPSS 0 %opensourcepos · open source point of sale17 дек. 2025 г.
- CVE-2025-7009222Наблюдать
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip
СредняяCVSS 5,5Эксплойта нетEPSS 0 %opensourcepos · open source point of sale12 февр. 2026 г.
- CVE-2026-2674521Наблюдать
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.
СредняяCVSS 5,3Эксплойта нетEPSS 0 %opensourcepos · open source point of sale20 февр. 2026 г.
- CVE-2026-3271221Наблюдать
Open Source Point of Sale has Stored XSS in Customer Name (Sales)
СредняяCVSS 5,4Эксплойта нетEPSS 0 %opensourcepos · open source point of sale7 апр. 2026 г.
- CVE-2026-3938021Наблюдать
Open Source Point of Sale has Stored XSS in Stock Location (Configuration)
СредняяCVSS 5,4Эксплойта нетEPSS 0 %opensourcepos · open source point of sale7 апр. 2026 г.
- CVE-2025-6865819Наблюдать
Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name field
СредняяCVSS 4,8Эксплойта нетEPSS 0 %opensourcepos · open source point of sale13 янв. 2026 г.