phppointofsale CVE Vulnerabilities & CVE List (12)

Products (CPE): — CVEs: 12

phppointofsale vulnerability overview

Aggregates CVE and security vulnerability intelligence across all phppointofsale-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk csrf, vendor risk ssrf, and vendor risk path handling and related problems; some flaws may lead to vendor impact session compromise and vendor impact file overwrite.

Vulnerability distribution trend (last 24 months)

Showing 112 of 12 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-41011 HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters. [email protected] 5.1 0.03% 2026-04-21 2026-05-06
CVE-2022-40296 The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems. [email protected] 9.8 0.36% 2022-10-31 2025-05-06
CVE-2022-40295 The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks. [email protected] 4.9 0.14% 2022-10-31 2026-02-25
CVE-2022-40294 The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers. [email protected] 8.8 0.47% 2022-10-31 2025-05-06
CVE-2022-40293 The application was vulnerable to a session fixation that could be used hijack accounts. [email protected] 9.8 0.36% 2022-10-31 2025-05-06
CVE-2022-40292 The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system. [email protected] 5.3 0.26% 2022-10-31 2025-05-06
CVE-2022-40291 The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to the site to delete their account, or in rare circumstances, hijack their account and create other admin accounts. [email protected] 8.8 0.13% 2022-10-31 2025-05-06
CVE-2022-40290 The application was vulnerable to an unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the barcode generation functionality, allowing attackers to generate an unsafe link that could compromise users. [email protected] 6.1 0.48% 2022-10-31 2025-05-06
CVE-2022-40289 The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files. [email protected] 9.0 1.02% 2022-10-31 2025-05-06
CVE-2022-40288 The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile. [email protected] 9.0 0.40% 2022-10-31 2025-05-06
CVE-2022-40287 The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messaging functionality, leading to privilege escalation or a compromise of a targeted account. [email protected] 9.0 0.40% 2022-10-31 2025-05-06
CVE-2011-3785 PHP Point Of Sale (POS) 10.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/scaffolding/views/view.php and certain other files. [email protected] 5.0 0.33% 2011-09-24 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence