Opensourcepos

Open Source Point Of Sale

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.16%
  • Veröffentlicht 13.02.2026 00:00:00
  • Zuletzt bearbeitet 17.02.2026 14:59:05

A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 13.02.2026 00:00:00
  • Zuletzt bearbeitet 17.02.2026 15:00:22

A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 13.02.2026 00:00:00
  • Zuletzt bearbeitet 17.02.2026 14:59:24

A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter.

Exploit
  • EPSS 0.2%
  • Veröffentlicht 12.02.2026 00:00:00
  • Zuletzt bearbeitet 18.02.2026 15:45:45

A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.

  • EPSS 0.19%
  • Veröffentlicht 13.01.2026 21:25:57
  • Zuletzt bearbeitet 21.01.2026 18:40:12

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration (Information) functionality. An au...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 17.12.2025 22:20:12
  • Zuletzt bearbeitet 18.12.2025 19:45:54

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the appli...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 17.12.2025 22:16:36
  • Zuletzt bearbeitet 18.12.2025 19:53:06

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS) vulnerability exists in the "Retu...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 19:52:51

A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 19:52:33

A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.

Exploit
  • EPSS 0.54%
  • Veröffentlicht 17.12.2025 00:00:00
  • Zuletzt bearbeitet 18.12.2025 19:52:17

A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.