Phppointofsale
Phppointofsale PHP Point OF Sale: vulnerabilidades y CVE
Phppointofsale PHP Point OF Sale tiene 12 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses1
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-41011 | Media (5.1) | 0.16% | — | 21 abr 2026 | HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to… |
| CVE-2022-40296 | Crítica (9.8) | 0.68% | — | 31 oct 2022 | The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other… |
| CVE-2022-40295 | Media (4.9) | 0.41% | — | 31 oct 2022 | The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks. |
| CVE-2022-40294 | Alta (8.8) | 0.81% | — | 31 oct 2022 | The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers. |
| CVE-2022-40293 | Crítica (9.8) | 0.68% | — | 31 oct 2022 | The application was vulnerable to a session fixation that could be used hijack accounts. |
| CVE-2022-40292 | Media (5.3) | 0.55% | — | 31 oct 2022 | The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system. |
| CVE-2022-40291 | Alta (8.8) | 0.32% | — | 31 oct 2022 | The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to the site to delete their account, or in rare circumstances, hijack… |
| CVE-2022-40290 | Media (6.1) | 0.41% | — | 31 oct 2022 | The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode generation functionality, allowing attackers to generate an unsafe link that could compromise users. |
| CVE-2022-40289 | Crítica (9) | 0.65% | — | 31 oct 2022 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce… |
| CVE-2022-40288 | Crítica (9) | 0.68% | — | 31 oct 2022 | The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their… |
| CVE-2022-40287 | Crítica (9) | 0.68% | — | 31 oct 2022 | The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account. |
| CVE-2011-3785 | Media (5) | 1.2% | — | 24 sept 2011 | PHP Point Of Sale (POS) 10.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by… |