Abacre develops point-of-sale systems for retail and restaurant environments, with observed vulnerabilities clustering around data-handling weaknesses including cleartext storage of sensitive information, cross-site scripting, and SQL injection. These are characteristic application-layer flaws in web-connected transaction systems where improper input handling and credential storage directly expose customer and payment data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Abacre over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67263MEDIUM Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients module. The application fails to properly sanitize user-suppl | Jan 20, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-65320HIGH Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound license ke | Dec 3, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-67261MEDIUM Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the Orders page. | Jan 20, 2026 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Abacre.
Media articles that mention a CVE ID that affects a product developed by Abacre — matched by CVE ID, not by vendor name.