cbcvebase.

Sourcecodester Simple Pos And Inventory System vulnerabilities

4 known vulnerabilities affecting sourcecodester/simple_pos_and_inventory_system.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2026-9447P3HIGHCVSS 7.3v1.02026-05-25
CVE-2026-9447 [HIGH] CWE-74 CVE-2026-9447: A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted elemen A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Name results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
cvelistv5nvd
CVE-2026-9445P3MEDIUMCVSS 6.3v1.02026-05-25
CVE-2026-9445 [MEDIUM] CWE-284 CVE-2026-9445: A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file /admin/addproduct.php of the component File Extension Handler. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.
cvelistv5nvd
CVE-2026-9446P4MEDIUMCVSS 4.7v1.02026-05-25
CVE-2026-9446 [MEDIUM] CWE-74 CVE-2026-9446: A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected e A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown function of the file /admin/edit_customer.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2026-9444P4MEDIUMCVSS 4.7v1.02026-05-25
CVE-2026-9444 [MEDIUM] CWE-74 CVE-2026-9444: A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affec A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
cvelistv5nvd
Sourcecodester Simple Pos And Inventory System vulnerabilities | cvebase