VendorsOpensourceposopen_source_point_of_saleany version
Vulnerabilities

Opensourcepos Open Source Point of Sale any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-32888
Open Source Point of Sale is Vulnerable to SQL Injection Through its Item Search Functionality
Published 2026-03-20 · Analyzed
8.8EPSS 0.005
CVE-2025-68434
opensourcepos has Cross-Site Request Forgery vulnerability that leads to Unauthorized Administrator Creation
Published 2025-12-17 · Analyzed
8.8EPSS 0.003
CVE-2025-68147
opensourcepos has a Cross-site Scripting vulnerability
Published 2025-12-17 · Analyzed
8.1EPSS 0.004
CVE-2026-33730
Open Source Point of Sale has an IDOR in Password Change (Home)
Published 2026-03-27 · Analyzed
6.5EPSS 0.004
CVE-2026-32712
Open Source Point of Sale has Stored XSS in Customer Name (Sales)
Published 2026-04-07 · Analyzed
5.4EPSS 0.002
CVE-2026-39380
Open Source Point of Sale has Stored XSS in Stock Location (Configuration)
Published 2026-04-07 · Analyzed
5.4EPSS 0.002
CVE-2025-68658
Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) – Company Name field
Published 2026-01-13 · Analyzed
4.8EPSS 0.002