VYPR

Point of Sales

by Point Of Sales

CVEs (3)

  • CVE-2018-18805CriNov 16, 2018
    risk 0.67cvss 9.8epss 0.05

    Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.

  • CVE-2020-29285CriDec 2, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.

  • CVE-2025-41011MedApr 21, 2026
    risk 0.40cvss 6.1epss 0.00

    HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y…