Ultimatefosters

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-70560

    Ultimate POS Stored XSS via First Name Field in Leave Notifications

    Last Modified: Aug 13, 2026
    Published: Aug 12, 2026

    CVE-2025-60503

    A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session, which could lead to session hijacking or other malicious actions.

    Last Modified: Feb 03, 2026
    Published: Nov 03, 2025
    Last Modified: Apr 15, 2026
    Published: Jul 31, 2025

    CVE-2018-17139

    UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type.

    Last Modified: Nov 21, 2024
    Published: Sep 17, 2018
    Items Per Page
    Ultimatefosters Vulnerabilities & Security CVEs | CVE-DB