Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.9)0.63%—Opensourcepos Open Source Point OF SaleAI15/8/202620/8/2026
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The…
AplazadaMedia (6.3)0.27%—Opensourcepos Open Source Point OF SaleAI18/5/202617/6/2026
A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have high complexity.…
AplazadaMedia (5.3)0.57%—Opensourcepos Open Source Point OF SaleAI18/5/202617/6/2026
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as…
AnalizadaMedia (5.4)0.24%—Opensourcepos Open Source Point OF Sale7/4/202624/7/2026
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer_name column is configured with escape: false in the bootstrap-table column…
AnalizadaMedia (5.4)0.24%—Opensourcepos Open Source Point OF Sale7/4/202624/7/2026
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied through the stock_location…
AnalizadaMedia (6.5)0.35%—Opensourcepos Open Source Point OF Sale27/3/202617/6/2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an authenticated low-privileged user to access the password change functionality of other users,…
AnalizadaAlta (8.8)0.46%—Opensourcepos Open Source Point OF Sale20/3/202617/6/2026
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search feature is enabled (search_custom filter), user-supplied input from the search GET parameter is…
AnalizadaAlta (8.8)0.82%—Opensourcepos Open Source Point OF Sale20/2/202617/6/2026
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).
AnalizadaMedia (5.3)0.43%—Opensourcepos Open Source Point OF Sale20/2/202617/6/2026
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This…
AnalizadaMedia (6.5)0.17%—Opensourcepos Open Source Point OF Sale13/2/202617/6/2026
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
AnalizadaMedia (6.5)0.17%—Opensourcepos Open Source Point OF Sale13/2/202617/6/2026
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter.
AnalizadaAlta (7.4)0.36%—Opensourcepos Open Source Point OF Sale13/2/202617/6/2026
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
AnalizadaMedia (6.5)0.17%—Opensourcepos Open Source Point OF Sale13/2/202617/6/2026
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter.
AnalizadaMedia (5.5)0.21%—Opensourcepos Open Source Point OF Sale12/2/202617/6/2026
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.
AnalizadaMedia (4.8)0.21%—Opensourcepos Open Source Point OF Sale13/1/202617/6/2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration (Information) functionality. An authenticated user with the permission “Configuration: Change OSPOS's…
AnalizadaAlta (8.8)0.28%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protection mechanism was…
AnalizadaAlta (8.1)0.38%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS) vulnerability exists in the "Return Policy" configuration field. The application does not properly…
AnalizadaMedia (6.1)0.26%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
AnalizadaAlta (7.2)0.55%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.
AnalizadaAlta (7.2)0.55%—Opensourcepos Open Source Point OF Sale17/12/202517/6/2026
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
AnalizadaAlta (7.5)0.45%—Opensourcepos Open Source Point OF Sale18/11/202517/6/2026
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns…
ModificadaAlta (7.2)1.2%—Opensourcepos Open Source Point OF Sale28/7/202217/6/2026
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
ModificadaMedia (4)1.3%—Open Source Point OF Sale Project Open Source Point OF Sale29/9/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Open Source Point of Sale 2.3.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.