Known Vulnerabilities for Php Point Of Sale by Phppointofsale
Listed below are 10 of the newest known vulnerabilities associated with "Php Point Of Sale" by "Phppointofsale".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42840 json | An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trig... | Not Provided | 2026-06-03 | 2026-06-03 |
| CVE-2026-42839 json | An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, descr... | Not Provided | 2026-06-03 | 2026-06-03 |
| CVE-2026-16078 json | The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all ver... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-8803 json | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file app/... | Not Provided | 2026-05-18 | 2026-05-18 |
| CVE-2026-8802 json | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicTh... | Not Provided | 2026-05-18 | 2026-05-18 |
| CVE-2026-6072 json | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-... | Not Provided | 2026-05-20 | 2026-05-20 |
| CVE-2025-41011 json | Not Provided | 2026-04-21 | 2026-05-06 | |
| CVE-2022-40296 json | The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpe... | 9.8 - CRITICAL | 2022-10-31 | 2023-10-25 |
| CVE-2022-40295 json | The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user pas... | 4.9 - MEDIUM | 2022-10-31 | 2023-10-25 |
| CVE-2022-40294 json | The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embe... | 8.8 - HIGH | 2022-10-31 | 2023-10-25 |