VendorsOpensourceposopen_source_point_of_saleall versions
Vulnerabilities

Opensourcepos Open Source Point of Sale

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2026-26746
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).
Published 2026-02-20 · Analyzed
8.8EPSS 0.008
CVE-2026-32888
Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality
Published 2026-03-20 · Analyzed
8.8EPSS 0.005
CVE-2025-68434
opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation
Published 2025-12-17 · Analyzed
8.8EPSS 0.003
CVE-2025-68147
opensourcepos has a Cross-site Scripting vulnerability
Published 2025-12-17 · Analyzed
8.1EPSS 0.004
CVE-2025-63800
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.
Published 2025-11-18 · Analyzed
7.5EPSS 0.005
CVE-2025-70093
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
Published 2026-02-13 · Analyzed
7.4EPSS 0.004
CVE-2022-34578
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
Published 2022-07-28 · Modified
7.2EPSS 0.012
CVE-2025-66921
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
Published 2025-12-17 · Analyzed
7.2EPSS 0.006
CVE-2025-66923
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.
Published 2025-12-17 · Analyzed
7.2EPSS 0.006
CVE-2026-33730
Open Source Point of Sale has an IDOR in Password Change (Home)
Published 2026-03-27 · Analyzed
6.5EPSS 0.004
CVE-2025-70094
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter.
Published 2026-02-13 · Analyzed
6.5EPSS 0.002
CVE-2025-70091
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter.
Published 2026-02-13 · Analyzed
6.5EPSS 0.002
CVE-2025-70095
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
Published 2026-02-13 · Analyzed
6.5EPSS 0.002
CVE-2025-66924
A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
Published 2025-12-17 · Analyzed
6.1EPSS 0.003
CVE-2025-70092
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.
Published 2026-02-12 · Analyzed
5.5EPSS 0.002
CVE-2026-32712
Open Source Point of Sale has Stored XSS in Customer Name (Sales)
Published 2026-04-07 · Analyzed
5.4EPSS 0.002
CVE-2026-39380
Open Source Point of Sale has Stored XSS in Stock Location (Configuration)
Published 2026-04-07 · Analyzed
5.4EPSS 0.002
CVE-2026-26745
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This allows an attacker with access to modify the currency_symbol value to inject arbitrary SQL expressions, which are executed when the affected query is subsequently processed.
Published 2026-02-20 · Analyzed
5.3EPSS 0.004
CVE-2025-68658
Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name field
Published 2026-01-13 · Analyzed
4.8EPSS 0.002