Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

PHP Point of Sale LLC — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting PHP Point of Sale LLC. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHP Point of Sale LLC develops an open-source point-of-sale system for retail businesses. Historically, their software has been vulnerable to multiple security issues, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities, with 10 CVEs documented. The application's web interface and database interactions have been common attack vectors. While no major public security incidents have been widely reported, the consistent presence of vulnerabilities in their codebase suggests ongoing security challenges that require diligent patch management and secure coding practices to mitigate potential risks for business users.

Top products by PHP Point of Sale LLC: PHP Point of Sale
CVE IDTitleCVSSSeverityPublished
CVE-2022-40294 CSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC — PHP Point of SaleCWE-1236 8.8 -2022-10-31
CVE-2022-40290 Reflected cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC. — PHP Point of SaleCWE-79 6.1 -2022-10-31
CVE-2022-40295 Authenticated sensitive information disclosure in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC. — PHP Point of SaleCWE-916 4.9 -2022-10-31
CVE-2022-40287 Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via user profile data fields. — PHP Point of SaleCWE-79 9.0 -2022-10-31
CVE-2022-40296 Server-side request forgery (SSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC. — PHP Point of SaleCWE-918 10.0 -2022-10-31
CVE-2022-40289 Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via file upload and download functionality. — PHP Point of SaleCWE-79 9.0 -2022-10-31
CVE-2022-40292 Unauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC. — PHP Point of SaleCWE-209 5.3 -2022-10-31
CVE-2022-40291 Cross-site request forgery (CSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC — PHP Point of SaleCWE-352 8.8 -2022-10-31
CVE-2022-40293 Session fixation in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC. — PHP Point of SaleCWE-384 8.1 -2022-10-31
CVE-2022-40288 Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via messaging functionality — PHP Point of SaleCWE-79 9.0 -2022-10-31

This page lists every published CVE security advisory associated with PHP Point of Sale LLC. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.