Public Security Vulnerability Disclosures
[CVE-2025-52022] Information disclosure via verbose error messages in Aptsys gemsloyalty backend
Summary An information disclosure vulnerability was identified in the backend of Aptsys’ gemsloyalty platform, which powers POS and management systems for multiple F&B clients. The issue allow...
[CVE-2025-52026] Unauthenticated data exposure in Aptsys gemscms backend
Summary An unauthenticated information disclosure vulnerability was identified in Aptsys’ gemscms backend platform. A publicly reachable API used in production deployments returns staff/cashier ac...
[CVE-2025-52025] SQL Injection vulnerability in Aptsys gemscms backend
Summary A SQL Injection vulnerability was identified in Aptsys’ gemscms backend platform, a shared backend used by multiple F&B businesses for POS and restaurant management. A vulnerable backe...
[CVE-2025-52024] Unauthenticated access to exposed developer web service panels in Aptsys POS backend
Summary A security misconfiguration vulnerability was identified in Aptsys’ POS Platform Web Services module, part of the gemscms backend platform used by multiple F&B businesses. Developer-or...
[CVE-2025-52023] Information disclosure via verbose error messages in Aptsys gemscms backend
Summary An information disclosure vulnerability was identified in the backend of Aptsys’ gemscms platform, which powers POS and management systems for multiple F&B clients. The issue allows un...