Opensourcepos Vulnerabilities

Comprehensive security vulnerability database for Opensourcepos products

Last updated: Feb 13, 2026
Total CVEs

4

Critical

0

With Exploits

0

Last 30 Days

4

Severity Distribution

Critical0
0%
High1
25%
Medium3
75%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2025-700956.5

This vulnerability allows attackers to run malicious scripts on the OpenSourcePOS platform, potentially stealing sensitive information from users or manipulating transactions. It occurs when an attacker can inject harmful code into the item management or sales invoice sections, which requires them to have access to those functions in the application.

opensourceposopen source point of sale
Theoretical
7 days agoFeb 13, 2026
CVE-2025-700946.5

This vulnerability allows attackers to run malicious scripts on a user's browser by injecting harmful code into the Item Category field when generating barcodes. It requires the attacker to have access to the web interface of OpenSourcePOS, making it important for users to be cautious about input validation and access controls.

opensourceposopen source point of sale
Theoretical
7 days agoFeb 13, 2026
CVE-2025-700937.4

This vulnerability allows attackers to run any code they want on the OpenSourcePOS system by sending a specially crafted response through AJAX. It requires the attacker to have access to the system's web interface, making it a serious risk if proper security measures are not in place.

opensourceposopen source point of sale
Theoretical
7 days agoFeb 13, 2026
CVE-2025-700916.5

This vulnerability allows attackers to run malicious scripts in a user's browser by injecting harmful code into the Phone Number field in the Customers function of OpenSourcePOS v3.4.1. It requires the attacker to trick a user into visiting a page where this code is executed, potentially leading to data theft or session hijacking.

opensourceposopen source point of sale
Theoretical
7 days agoFeb 13, 2026

About Opensourcepos Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Opensourcepos products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.