Opensourcepos
Opensourcepos Open Source Point OF Sale: vulnerabilities and CVEs
Opensourcepos Open Source Point OF Sale has 22 published vulnerabilities, 21 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs22
Last 12 months21
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19895 | Low (2.9) | 0.63% | — | Aug 15, 2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in… |
| CVE-2026-8803 | Medium (6.3) | 0.27% | — | May 18, 2026 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak… |
| CVE-2026-8802 | Medium (5.3) | 0.57% | — | May 18, 2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename… |
| CVE-2026-32712 | Medium (5.4) | 0.24% | — | Apr 7, 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management… |
| CVE-2026-39380 | Medium (5.4) | 0.24% | — | Apr 7, 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations… |
| CVE-2026-33730 | Medium (6.5) | 0.35% | — | Mar 27, 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an… |
| CVE-2026-32888 | High (8.8) | 0.46% | — | Mar 20, 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search… |
| CVE-2026-26746 | High (8.8) | 0.82% | — | Feb 20, 2026 | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration.… |
| CVE-2026-26745 | Medium (5.3) | 0.43% | — | Feb 20, 2026 | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated… |
| CVE-2025-70095 | Medium (6.5) | 0.17% | — | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. |
| CVE-2025-70094 | Medium (6.5) | 0.17% | — | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category… |
| CVE-2025-70093 | High (7.4) | 0.36% | — | Feb 13, 2026 | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response. |
| CVE-2025-70091 | Medium (6.5) | 0.17% | — | Feb 13, 2026 | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter. |
| CVE-2025-70092 | Medium (5.5) | 0.20% | — | Feb 12, 2026 | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter. |
| CVE-2025-68658 | Medium (4.8) | 0.21% | — | Jan 13, 2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration… |
| CVE-2025-68434 | High (8.8) | 0.28% | — | Dec 17, 2025 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF)… |
| CVE-2025-68147 | High (8.1) | 0.38% | — | Dec 17, 2025 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS)… |
| CVE-2025-66924 | Medium (6.1) | 0.26% | — | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter. |
| CVE-2025-66923 | High (7.2) | 0.55% | — | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter. |
| CVE-2025-66921 | High (7.2) | 0.55% | — | Dec 17, 2025 | A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter. |
| CVE-2025-63800 | High (7.5) | 0.45% | — | Nov 18, 2025 | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the… |
| CVE-2022-34578 | High (7.2) | 1.2% | — | Jul 28, 2022 | Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.