CVE-2025-70092
- EPSS 0.02%
- Veröffentlicht 12.02.2026 00:00:00
- Zuletzt bearbeitet 18.02.2026 15:45:45
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.
CVE-2025-68658
- EPSS 0.04%
- Veröffentlicht 13.01.2026 21:25:57
- Zuletzt bearbeitet 21.01.2026 18:40:12
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration (Information) functionality. An au...
CVE-2025-68434
- EPSS 0.13%
- Veröffentlicht 17.12.2025 22:20:12
- Zuletzt bearbeitet 18.12.2025 19:45:54
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the appli...
CVE-2025-68147
- EPSS 0.05%
- Veröffentlicht 17.12.2025 22:16:36
- Zuletzt bearbeitet 18.12.2025 19:53:06
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS) vulnerability exists in the "Retu...
CVE-2025-66924
- EPSS 0.07%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:52:51
A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
CVE-2025-66923
- EPSS 0.24%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:52:33
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.
CVE-2025-66921
- EPSS 0.24%
- Veröffentlicht 17.12.2025 00:00:00
- Zuletzt bearbeitet 18.12.2025 19:52:17
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
CVE-2025-63800
- EPSS 0.34%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 16:51:22
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` param...
CVE-2022-34578
- EPSS 0.45%
- Veröffentlicht 28.07.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:09:47
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.