CVE-2025-67263
MEDIUMAbacre Retail Point OF Sale - XSS
Title source: ruleDescription
Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients module. The application fails to properly sanitize user-supplied input stored in the Name and Surname fields. An attacker can insert malicious HTML or script content into these fields, which, persisted in the database.
Exploits (1)
Scores
CVSS v3
6.1
EPSS
0.0004
EPSS Percentile
11.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
abacre/retail_point_of_sale
14.0.0.396
Published
Jan 20, 2026
Tracked Since
Feb 18, 2026