« Back to list

Opensourcepos

Opensourcepos Open Source Point OF Sale: vulnerabilities and CVEs

Opensourcepos Open Source Point OF Sale has 22 published vulnerabilities, 21 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs22
Last 12 months21
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-19895Low (2.9)0.63%—Aug 15, 2026
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in…
CVE-2026-8803Medium (6.3)0.27%—May 18, 2026
A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak…
CVE-2026-8802Medium (5.3)0.57%—May 18, 2026
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename…
CVE-2026-32712Medium (5.4)0.24%—Apr 7, 2026
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management…
CVE-2026-39380Medium (5.4)0.24%—Apr 7, 2026
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations…
CVE-2026-33730Medium (6.5)0.35%—Mar 27, 2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an…
CVE-2026-32888High (8.8)0.46%—Mar 20, 2026
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search…
CVE-2026-26746High (8.8)0.82%—Feb 20, 2026
OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration.…
CVE-2026-26745Medium (5.3)0.43%—Feb 20, 2026
OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated…
CVE-2025-70095Medium (6.5)0.17%—Feb 13, 2026
A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
CVE-2025-70094Medium (6.5)0.17%—Feb 13, 2026
A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category…
CVE-2025-70093High (7.4)0.36%—Feb 13, 2026
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
CVE-2025-70091Medium (6.5)0.17%—Feb 13, 2026
A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter.
CVE-2025-70092Medium (5.5)0.20%—Feb 12, 2026
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.
CVE-2025-68658Medium (4.8)0.21%—Jan 13, 2026
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration…
CVE-2025-68434High (8.8)0.28%—Dec 17, 2025
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF)…
CVE-2025-68147High (8.1)0.38%—Dec 17, 2025
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Stored Cross-Site Scripting (XSS)…
CVE-2025-66924Medium (6.1)0.26%—Dec 17, 2025
A Cross-site scripting (XSS) vulnerability in Create/Update Item Kit(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
CVE-2025-66923High (7.2)0.55%—Dec 17, 2025
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.
CVE-2025-66921High (7.2)0.55%—Dec 17, 2025
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the "name" parameter.
CVE-2025-63800High (7.5)0.45%—Nov 18, 2025
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the…
CVE-2022-34578High (7.2)1.2%—Jul 28, 2022
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application4
  2. T1059.007 JavaScript3
  3. T1005 Data from Local System2
  4. T1210 Exploitation of Remote Services2
  5. T1059 Command and Scripting Interpreter1
  6. T1078.001 Default Accounts1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.