Opensourcepos
Opensourcepos Open Source Point OF Sale: vulnerabilidades y CVE
Opensourcepos Open Source Point OF Sale tiene 22 vulnerabilidades publicadas, 21 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses21
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19895 | Baja (2.9) | 0.63% | — | 15 ago 2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in… |
| CVE-2026-8803 | Media (6.3) | 0.27% | — | 18 may 2026 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak… |
| CVE-2026-8802 | Media (5.3) | 0.57% | — | 18 may 2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename… |
| CVE-2026-32712 | Media (5.4) | 0.24% | — | 7 abr 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management… |
| CVE-2026-39380 | Media (5.4) | 0.24% | — | 7 abr 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations… |
| CVE-2026-33730 | Media (6.5) | 0.35% | — | 27 mar 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an… |
| CVE-2026-32888 | Alta (8.8) | 0.46% | — | 20 mar 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search… |
| CVE-2026-26746 | Alta (8.8) | 0.82% | — | 20 feb 2026 | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration.… |
| CVE-2026-26745 | Media (5.3) | 0.43% | — | 20 feb 2026 | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated… |
| CVE-2025-70095 | Media (6.5) | 0.17% | — | 13 feb 2026 | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. |
| CVE-2025-70094 | Media (6.5) | 0.17% | — | 13 feb 2026 | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category… |
| CVE-2025-70093 | Alta (7.4) | 0.36% | — | 13 feb 2026 | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response. |
| CVE-2025-70091 | Media (6.5) | 0.17% | — | 13 feb 2026 | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter. |
| CVE-2025-70092 | Media (5.5) | 0.21% | — | 12 feb 2026 | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter. |
| CVE-2025-68658 | Media (4.8) | 0.21% | — | 13 ene 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration… |
| CVE-2025-68434 | Alta (8.8) | 0.28% | — | 17 dic 2025 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF)… |
| CVE-2025-68147 | Alta (8.1) | 0.38% | — | 17 dic 2025 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS)… |
| CVE-2025-66924 | Media (6.1) | 0.26% | — | 17 dic 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter. |
| CVE-2025-66923 | Alta (7.2) | 0.55% | — | 17 dic 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter. |
| CVE-2025-66921 | Alta (7.2) | 0.55% | — | 17 dic 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter. |
| CVE-2025-63800 | Alta (7.5) | 0.45% | — | 18 nov 2025 | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the… |
| CVE-2022-34578 | Alta (7.2) | 1.2% | — | 28 jul 2022 | Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.