Vulnerabilities in PHP Point of Sale LLC
10 resultsVexday analysis
PHP Point of Sale LLC acumula 10 vulnerabilidades em sua base, sendo 5 delas críticas, porém nenhuma está sob exploração ativa conhecida no momento. A fraqueza dominante é injeção cross-site (CWE-79), típica de aplicações web mal sanitizadas, e a ausência de publicações recentes sugere que o risco atual é estável, embora o volume de falhas críticas justifique atenção contínua.
CVE-2022-40294HIGHCSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLCEPSS 0.8%CVE-2022-40287CRITICALStored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via user profile data fields.EPSS 0.7%CVE-2022-40293CRITICALSession fixation in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.7%CVE-2022-40288CRITICALStored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via messaging functionalityEPSS 0.7%CVE-2022-40296CRITICALServer-side request forgery (SSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.7%CVE-2022-40289CRITICALStored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via file upload and download functionality.EPSS 0.6%CVE-2022-40292MEDIUMUnauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.5%CVE-2022-40290MEDIUMReflected cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.4%CVE-2022-40295—Authenticated sensitive information disclosure in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.4%CVE-2022-40291HIGHCross-site request forgery (CSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, LLCEPSS 0.3%