opensourcepos kayıtları
opensourcepos üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %26,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-20 Improper Input Validation2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2026-26746Kavram kanıtı | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.opensourcepos · open source point of sale · CWE-434 | Yüksek8,8 | — | %0,8 | 20 Şub 2026 |
35İzleyin | CVE-2026-32888İstismar yok | Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionalityopensourcepos · open source point of sale · CWE-89 | Yüksek8,8 | — | %0,5 | 19 Mar 2026 |
35İzleyin | CVE-2025-68434Kavram kanıtı | opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creationopensourcepos · open source point of sale · CWE-352 | Yüksek8,8 | — | %0,3 | 17 Ara 2025 |
32İzleyin | CVE-2025-68147Kavram kanıtı | opensourcepos has a Cross-site Scripting vulnerabilityopensourcepos · open source point of sale · CWE-79 | Yüksek8,1 | — | %0,4 | 17 Ara 2025 |
30İzleyin | CVE-2025-63800İstismar yok | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missingopensourcepos · open source point of sale · CWE-521 | Yüksek7,5 | — | %0,5 | 18 Kas 2025 |
29İzleyin | CVE-2025-70093İstismar yok | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.opensourcepos · open source point of sale · CWE-77 | Yüksek7,4 | — | %0,4 | 13 Şub 2026 |
28İzleyin | CVE-2022-34578İstismar yok | Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.opensourcepos · open source point of sale · CWE-434 | Yüksek7,2 | — | %1,2 | 28 Tem 2022 |
28İzleyin | CVE-2025-66921İstismar yok | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inopensourcepos · open source point of sale · CWE-20 | Yüksek7,2 | — | %0,6 | 17 Ara 2025 |
28İzleyin | CVE-2025-66923İstismar yok | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injecopensourcepos · open source point of sale · CWE-20 | Yüksek7,2 | — | %0,6 | 17 Ara 2025 |
26İzleyin | CVE-2026-33730İstismar yok | Open Source Point of Sale has an IDOR in Password Change (Home)opensourcepos · open source point of sale · CWE-639 | Orta6,5 | — | %0,4 | 26 Mar 2026 |
26İzleyin | CVE-2025-70094İstismar yok | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitraopensourcepos · open source point of sale · CWE-79 | Orta6,5 | — | %0,2 | 13 Şub 2026 |
26İzleyin | CVE-2025-70091İstismar yok | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripopensourcepos · open source point of sale · CWE-79 | Orta6,5 | — | %0,2 | 13 Şub 2026 |
26İzleyin | CVE-2025-70095İstismar yok | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exeopensourcepos · open source point of sale · CWE-79 | Orta6,5 | — | %0,2 | 13 Şub 2026 |
24İzleyin | CVE-2025-66924İstismar yok | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injecopensourcepos · open source point of sale · CWE-79 | Orta6,1 | — | %0,3 | 17 Ara 2025 |
22İzleyin | CVE-2025-70092İstismar yok | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripopensourcepos · open source point of sale · CWE-79 | Orta5,5 | — | %0,2 | 12 Şub 2026 |
21İzleyin | CVE-2026-26745İstismar yok | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.opensourcepos · open source point of sale · CWE-89 | Orta5,3 | — | %0,4 | 20 Şub 2026 |
21İzleyin | CVE-2026-32712İstismar yok | Open Source Point of Sale has Stored XSS in Customer Name (Sales)opensourcepos · open source point of sale · CWE-79 | Orta5,4 | — | %0,2 | 7 Nis 2026 |
21İzleyin | CVE-2026-39380İstismar yok | Open Source Point of Sale has Stored XSS in Stock Location (Configuration)opensourcepos · open source point of sale · CWE-79 | Orta5,4 | — | %0,2 | 7 Nis 2026 |
19İzleyin | CVE-2025-68658İstismar yok | Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name fieldopensourcepos · open source point of sale · CWE-79 | Orta4,8 | — | %0,2 | 13 Oca 2026 |
- CVE-2026-2674635İzleyin
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.
YüksekCVSS 8,8Kavram kanıtıEPSS %1opensourcepos · open source point of sale20 Şub 2026
- CVE-2026-3288835İzleyin
Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality
YüksekCVSS 8,8İstismar yokEPSS %0opensourcepos · open source point of sale19 Mar 2026
- CVE-2025-6843435İzleyin
opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation
YüksekCVSS 8,8Kavram kanıtıEPSS %0opensourcepos · open source point of sale17 Ara 2025
- CVE-2025-6814732İzleyin
opensourcepos has a Cross-site Scripting vulnerability
YüksekCVSS 8,1Kavram kanıtıEPSS %0opensourcepos · open source point of sale17 Ara 2025
- CVE-2025-6380030İzleyin
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing
YüksekCVSS 7,5İstismar yokEPSS %0opensourcepos · open source point of sale18 Kas 2025
- CVE-2025-7009329İzleyin
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
YüksekCVSS 7,4İstismar yokEPSS %0opensourcepos · open source point of sale13 Şub 2026
- CVE-2022-3457828İzleyin
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
YüksekCVSS 7,2İstismar yokEPSS %1opensourcepos · open source point of sale28 Tem 2022
- CVE-2025-6692128İzleyin
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to in
YüksekCVSS 7,2İstismar yokEPSS %1opensourcepos · open source point of sale17 Ara 2025
- CVE-2025-6692328İzleyin
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec
YüksekCVSS 7,2İstismar yokEPSS %1opensourcepos · open source point of sale17 Ara 2025
- CVE-2026-3373026İzleyin
Open Source Point of Sale has an IDOR in Password Change (Home)
OrtaCVSS 6,5İstismar yokEPSS %0opensourcepos · open source point of sale26 Mar 2026
- CVE-2025-7009426İzleyin
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitra
OrtaCVSS 6,5İstismar yokEPSS %0opensourcepos · open source point of sale13 Şub 2026
- CVE-2025-7009126İzleyin
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip
OrtaCVSS 6,5İstismar yokEPSS %0opensourcepos · open source point of sale13 Şub 2026
- CVE-2025-7009526İzleyin
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exe
OrtaCVSS 6,5İstismar yokEPSS %0opensourcepos · open source point of sale13 Şub 2026
- CVE-2025-6692424İzleyin
A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec
OrtaCVSS 6,1İstismar yokEPSS %0opensourcepos · open source point of sale17 Ara 2025
- CVE-2025-7009222İzleyin
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip
OrtaCVSS 5,5İstismar yokEPSS %0opensourcepos · open source point of sale12 Şub 2026
- CVE-2026-2674521İzleyin
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.
OrtaCVSS 5,3İstismar yokEPSS %0opensourcepos · open source point of sale20 Şub 2026
- CVE-2026-3271221İzleyin
Open Source Point of Sale has Stored XSS in Customer Name (Sales)
OrtaCVSS 5,4İstismar yokEPSS %0opensourcepos · open source point of sale7 Nis 2026
- CVE-2026-3938021İzleyin
Open Source Point of Sale has Stored XSS in Stock Location (Configuration)
OrtaCVSS 5,4İstismar yokEPSS %0opensourcepos · open source point of sale7 Nis 2026
- CVE-2025-6865819İzleyin
Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name field
OrtaCVSS 4,8İstismar yokEPSS %0opensourcepos · open source point of sale13 Oca 2026