Point of Sales
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-18805 | Cri | 0.67 | 9.8 | 0.05 | Nov 16, 2018 | Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb. | ||
| CVE-2020-29285 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2020 | SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php. | ||
| CVE-2025-41011 | Med | 0.40 | 6.1 | 0.00 | Apr 21, 2026 | HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y… |
- risk 0.67cvss 9.8epss 0.05
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.
- risk 0.40cvss 6.1epss 0.00
HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y…