CVE-2025-70094
Awaiting Analysis Awaiting Analysis - Queue

Cross-Site Scripting in OpenSourcePOS Barcode Generation Function

Vulnerability report for CVE-2025-70094, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-13

Last updated on: 2026-02-17

Assigner: MITRE

Description

A cross-site scripting (XSS) vulnerability in the Generate Item Barcode function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Category parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-13
Last Modified
2026-02-17
Generated
2026-07-28
AI Q&A
2026-02-13
EPSS Evaluated
2026-07-26
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opensourcepos open_source_point_of_sale 3.4.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) issue found in the Generate Item Barcode function of OpenSourcePOS version 3.4.1.

Attackers can exploit this vulnerability by injecting a crafted payload into the Item Category parameter, which allows them to execute arbitrary web scripts or HTML.

Detection Guidance

I don't know

Impact Analysis

Exploitation of this XSS vulnerability can allow attackers to run malicious scripts in the context of the affected application.

  • Steal sensitive user information such as session cookies.
  • Perform unauthorized actions on behalf of legitimate users.
  • Deface or manipulate the web interface.
  • Potentially spread malware or redirect users to malicious sites.
Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-70094. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart