CVE-2025-10028: Facebook-Kimmymatillano Point Of Sale System

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the argument scripts leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used.

Affected products

Published 2025-09-06. Last modified 2026-06-17.