CVE-2026-32712: Opensourcepos Open Source Point Of Sale

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer_name column is configured with escape: false in the bootstrap-table column configuration, causing customer names to be rendered as raw HTML. An attacker with customer management permissions can inject arbitrary JavaScript into a customer's first_name or last_name field, which executes in the browser of any user viewing the Daily Sales page. This vulnerability is fixed in 3.4.3.

Affected products

  • Opensourcepos Open Source Point Of Sale: before 3.4.3 (fixed in 3.4.3)

Published 2026-04-07. Last modified 2026-07-24.