CVE-2026-5561: Campcodes Complete Pos Management And Inventory System

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was determined in Campcodes Complete POS Management and Inventory System up to 4.0.6. This affects an unknown function of the file app/Http/Controllers/SettingsController.php of the component Environment Variable Handler. Executing a manipulation can lead to injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

Affected products

  • Campcodes Complete Pos Management And Inventory System: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …

Published 2026-04-05. Last modified 2026-07-24.