Vulnerabilities
Summary — last 7 days
New vulnerabilities3,006▼ 69 vs. last week
Critical / high1,420▲ 54 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)382▼ 128 vs. last week
113 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (2.9) | 0.63% | — | Opensourcepos Open Source Point OF SaleAI | 8/15/2026 | 8/20/2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::index of the file app/Config/Filters.php of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. The… | |
| Deferred | Medium (6.3) | 0.27% | — | Opensourcepos Open Source Point OF SaleAI | 5/18/2026 | 6/17/2026 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/Models/Employee.php of the component Employee Login. This manipulation causes use of weak hash. Remote exploitation of the attack is possible. The attack is considered to have high complexity.… | |
| Deferred | Medium (5.3) | 0.57% | — | Opensourcepos Open Source Point OF SaleAI | 5/18/2026 | 6/17/2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as… | |
| Analyzed | Medium (5.1) | 0.16% | — | Phppointofsale PHP Point OF Sale | 4/21/2026 | 6/17/2026 | HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters. | |
| Analyzed | Medium (5.4) | 0.24% | — | Opensourcepos Open Source Point OF Sale | 4/7/2026 | 7/24/2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer_name column is configured with escape: false in the bootstrap-table column… | |
| Analyzed | Medium (5.4) | 0.24% | — | Opensourcepos Open Source Point OF Sale | 4/7/2026 | 7/24/2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied through the stock_location… | |
| Analyzed | Medium (6.5) | 0.35% | — | Opensourcepos Open Source Point OF Sale | 3/27/2026 | 6/17/2026 | Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an authenticated low-privileged user to access the password change functionality of other users,… | |
| Analyzed | High (8.8) | 0.46% | — | Opensourcepos Open Source Point OF Sale | 3/20/2026 | 6/17/2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. When the custom attribute search feature is enabled (search_custom filter), user-supplied input from the search GET parameter is… | |
| Analyzed | Low (2.7) | 0.34% | — | Oretnom23 Pharmacy Point OF Sale System | 3/3/2026 | 6/17/2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php. | |
| Analyzed | Low (2.7) | 0.34% | — | Oretnom23 Pharmacy Point OF Sale System | 3/3/2026 | 6/17/2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_stock.php. | |
| Analyzed | Low (2.7) | 0.34% | — | Oretnom23 Pharmacy Point OF Sale System | 3/3/2026 | 6/17/2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_supplier.php. | |
| Analyzed | Low (2.7) | 0.34% | — | Oretnom23 Pharmacy Point OF Sale System | 3/3/2026 | 6/17/2026 | Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_product.php. | |
| Modified | Critical (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 3/2/2026 | 6/17/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. | |
| Modified | Critical (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 3/2/2026 | 6/17/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php. | |
| Analyzed | Critical (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 3/2/2026 | 6/17/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php. | |
| Analyzed | Critical (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 3/2/2026 | 6/17/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php. | |
| Analyzed | Critical (9.8) | 0.52% | — | Oretnom23 Pharmacy Point OF Sale System | 3/2/2026 | 6/17/2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. | |
| Analyzed | High (8.8) | 0.82% | — | Opensourcepos Open Source Point OF Sale | 2/20/2026 | 6/17/2026 | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE). | |
| Analyzed | Medium (5.3) | 0.43% | — | Opensourcepos Open Source Point OF Sale | 2/20/2026 | 6/17/2026 | OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This… | |
| Analyzed | Medium (6.5) | 0.17% | — | Opensourcepos Open Source Point OF Sale | 2/13/2026 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in the item management and sales invoice function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analyzed | Medium (6.5) | 0.17% | — | Opensourcepos Open Source Point OF Sale | 2/13/2026 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter. | |
| Analyzed | High (7.4) | 0.36% | — | Opensourcepos Open Source Point OF Sale | 2/13/2026 | 6/17/2026 | An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response. | |
| Analyzed | Medium (6.5) | 0.17% | — | Opensourcepos Open Source Point OF Sale | 2/13/2026 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in the Customers function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Phone Number parameter. | |
| Analyzed | Medium (5.5) | 0.21% | — | Opensourcepos Open Source Point OF Sale | 2/12/2026 | 6/17/2026 | A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter. | |
| Analyzed | Medium (6.1) | 0.20% | — | Abacre Retail Point OF Sale | 1/20/2026 | 6/17/2026 | Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients module. The application fails to properly sanitize user-supplied input stored in the Name and Surname fields. An attacker can insert malicious HTML or script content into these fields, which,… |