PatchSiren

opensourcepos CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM opensourcepos CVE published 2026-05-18

CVE-2026-8803

CVE-2026-8803 is reported against opensourcepos Open Source Point of Sale up to 3.4.2 and points to the Employee Login flow in app/Models/Employee.php. The reported issue involves weak hash handling and is described as remotely reachable, but with high complexity and difficult exploitability. Importantly, the vendor says the legacy code remains to support an upgrade path, that the default password is init [truncated]

MEDIUM opensourcepos CVE published 2026-05-18

CVE-2026-8802

CVE-2026-8802 describes a path traversal flaw in OpenSourcePOS Open Source Point of Sale up to version 3.4.2. The issue is in `getPicThumb` within `app/Controllers/Items.php`, where the `pic_filename` argument can be manipulated to reach unintended file paths. The vulnerability is remotely reachable and has a published fix in commit `def0c27a0e252668df8d942fc31e16d1edfd7323`. NVD lists the issue as CWE-22 [truncated]

MEDIUM opensourcepos CVE published 2026-04-07

CVE-2026-32712

CVE-2026-32712 is a Stored Cross-Site Scripting (XSS) vulnerability in Open Source Point of Sale (3.4.2 and earlier). The vulnerability exists in the Daily Sales management table, where the customer_name column is configured with escape: false, causing customer names to be rendered as raw HTML. An attacker with customer management permissions can inject arbitrary JavaScript into a customer's first_name or [truncated]

MEDIUM opensourcepos CVE published 2026-04-07

CVE-2026-39380

CVE-2026-39380 is a Stored Cross-Site Scripting (XSS) vulnerability in Open Source Point of Sale prior to 3.4.3. The application fails to properly sanitize user input supplied through the stock_location parameter, allowing attackers to inject malicious JavaScript code that is stored in the database and executed when rendered in the Employees interface. The vulnerability has a CVSS score of 5.4 and is clas [truncated]