VendorsPhp Point Of Salephp_point_of_saleall versions
Vulnerabilities

Php Point Of Sale PHP Point Of Sale

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2022-40293
Session fixation in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.
Published 2022-10-31 · Modified
9.8EPSS 0.007
CVE-2022-40296
Server-side request forgery (SSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.
Published 2022-10-31 · Modified
9.8EPSS 0.007
CVE-2022-40287
Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via user profile data fields.
Published 2022-10-31 · Modified
9.0EPSS 0.007
CVE-2022-40288
Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via messaging functionality
Published 2022-10-31 · Modified
9.0EPSS 0.007
CVE-2022-40289
Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via file upload and download functionality.
Published 2022-10-31 · Modified
9.0EPSS 0.006
CVE-2022-40294
CSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC
Published 2022-10-31 · Modified
8.8EPSS 0.008
CVE-2022-40291
Cross-site request forgery (CSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC
Published 2022-10-31 · Modified
8.8EPSS 0.003
CVE-2022-40290
Reflected cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.
Published 2022-10-31 · Modified
6.1EPSS 0.004
CVE-2025-41011
HTML injection in PHP Point Of Sale
Published 2026-04-21 · Analyzed
6.1EPSS 0.002
CVE-2022-40292
Unauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.
Published 2022-10-31 · Modified
5.3EPSS 0.005
CVE-2011-3785
PHP Point Of Sale (POS) 10.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files.
Published 2011-09-24 · Modified
5.0EPSS 0.012
CVE-2022-40295
Authenticated sensitive information disclosure in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.
Published 2022-10-31 · Modified
4.9EPSS 0.004