Opensourcepos develops an open-source point-of-sale system whose vulnerability footprint recurs around a single widely deployed product, with the durable signal centered on web application input handling and access control. The recurring weakness classes—including cross-site scripting, SQL injection, improper input validation, unrestricted file uploads, and authorization bypass—reflect the authentication and data-processing demands typical of retail-facing web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensourcepos over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32888HIGH Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. | Mar 20, 2026 | 8.8 | 30 | NO | NO |
CVE-2025-68434HIGH Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, | Dec 17, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-68147HIGH Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, | Dec 17, 2025 | 8.1 | 26 | NO | NO |
CVE-2026-26746HIGH OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulat | Feb 20, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-63800HIGH The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authent | Nov 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-66921HIGH A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via th | Dec 17, 2025 | 7.2 | 24 | NO | NO |
CVE-2022-34578HIGH Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. | Jul 28, 2022 | 7.2 | 24 | NO | NO |
CVE-2025-66923HIGH A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the p | Dec 17, 2025 | 7.2 | 23 | NO | NO |
CVE-2026-33730MEDIUM Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Ref | Mar 27, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-70093HIGH An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response. | Feb 13, 2026 | 7.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensourcepos.
Media articles that mention a CVE ID that affects a product developed by Opensourcepos — matched by CVE ID, not by vendor name.