CVE-2026-9444: Sourcecodester Simple Pos And Inventory System
Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function delete of the file /admin/deleteproduct.php of the component GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Affected products
- Sourcecodester Simple Pos And Inventory System: version 1.0 only
Published 2026-05-25. Last modified 2026-07-23.