İçeriğe atla
Noroxi

opensourcepos kayıtları

opensourcepos üreticisine ait 19 yayımlanmış kayıt.

Tüm kayıtlar

19 kayıt
  • CVE-2026-26746
    35İzleyin

    OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function.

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    opensourcepos · open source point of sale20 Şub 2026

  • CVE-2026-32888
    35İzleyin

    Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality

    YüksekCVSS 8,8İstismar yokEPSS %0

    opensourcepos · open source point of sale19 Mar 2026

  • CVE-2025-68434
    35İzleyin

    opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation

    YüksekCVSS 8,8Kavram kanıtıEPSS %0

    opensourcepos · open source point of sale17 Ara 2025

  • CVE-2025-68147
    32İzleyin

    opensourcepos has a Cross-site Scripting vulnerability

    YüksekCVSS 8,1Kavram kanıtıEPSS %0

    opensourcepos · open source point of sale17 Ara 2025

  • CVE-2025-63800
    30İzleyin

    The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing

    YüksekCVSS 7,5İstismar yokEPSS %0

    opensourcepos · open source point of sale18 Kas 2025

  • CVE-2025-70093
    29İzleyin

    An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.

    YüksekCVSS 7,4İstismar yokEPSS %0

    opensourcepos · open source point of sale13 Şub 2026

  • CVE-2022-34578
    28İzleyin

    Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

    YüksekCVSS 7,2İstismar yokEPSS %1

    opensourcepos · open source point of sale28 Tem 2022

  • CVE-2025-66921
    28İzleyin

    A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to in

    YüksekCVSS 7,2İstismar yokEPSS %1

    opensourcepos · open source point of sale17 Ara 2025

  • CVE-2025-66923
    28İzleyin

    A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec

    YüksekCVSS 7,2İstismar yokEPSS %1

    opensourcepos · open source point of sale17 Ara 2025

  • CVE-2026-33730
    26İzleyin

    Open Source Point of Sale has an IDOR in Password Change (Home)

    OrtaCVSS 6,5İstismar yokEPSS %0

    opensourcepos · open source point of sale26 Mar 2026

  • CVE-2025-70094
    26İzleyin

    A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitra

    OrtaCVSS 6,5İstismar yokEPSS %0

    opensourcepos · open source point of sale13 Şub 2026

  • CVE-2025-70091
    26İzleyin

    A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip

    OrtaCVSS 6,5İstismar yokEPSS %0

    opensourcepos · open source point of sale13 Şub 2026

  • CVE-2025-70095
    26İzleyin

    A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to exe

    OrtaCVSS 6,5İstismar yokEPSS %0

    opensourcepos · open source point of sale13 Şub 2026

  • CVE-2025-66924
    24İzleyin

    A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to injec

    OrtaCVSS 6,1İstismar yokEPSS %0

    opensourcepos · open source point of sale17 Ara 2025

  • CVE-2025-70092
    22İzleyin

    A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scrip

    OrtaCVSS 5,5İstismar yokEPSS %0

    opensourcepos · open source point of sale12 Şub 2026

  • CVE-2026-26745
    21İzleyin

    OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field.

    OrtaCVSS 5,3İstismar yokEPSS %0

    opensourcepos · open source point of sale20 Şub 2026

  • CVE-2026-32712
    21İzleyin

    Open Source Point of Sale has Stored XSS in Customer Name (Sales)

    OrtaCVSS 5,4İstismar yokEPSS %0

    opensourcepos · open source point of sale7 Nis 2026

  • CVE-2026-39380
    21İzleyin

    Open Source Point of Sale has Stored XSS in Stock Location (Configuration)

    OrtaCVSS 5,4İstismar yokEPSS %0

    opensourcepos · open source point of sale7 Nis 2026

  • CVE-2025-68658
    19İzleyin

    Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name field

    OrtaCVSS 4,8İstismar yokEPSS %0

    opensourcepos · open source point of sale13 Oca 2026