Product
phppointofsale php point of sale
13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-41011
CVE-2022-40296
CVE-2022-40295
CVE-2022-40294
CVE-2022-40293
CVE-2022-40292
CVE-2022-40291
CVE-2022-40290
CVE-2022-40289
CVE-2022-40288
CVE-2022-40287
CVE-2011-3785
CVE-2007-1477
all versions
HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's brow
all versions
The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected e
all versions
The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords
all versions
The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded w
all versions
The application was vulnerable to a session fixation that could be used hijack accounts.
all versions
The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on
all versions
The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending mal
all versions
The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode generation
all versions
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, whi
all versions
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could
all versions
The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functi
all versions
PHP Point Of Sale (POS) 10.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which re
all versions
Directory traversal vulnerability in index.php in PHP Point Of Sale for osCommerce 1.1 allows remote attackers to include and exec