Open Source Point Of Sale
Vendor:
First CVE: Jul 28, 2022 · Active for 3 years
19
Total CVEs
More Total CVEs than 95% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Open Source Point Of Sale over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 28, 2022
3 years ago
Most Recent CVE
Apr 7, 2026
112 days ago
CVE Severity & Scoring
Open Source Point Of Sale19 CVEs
53%
47%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None9 (47.4%)
Unknown0 (0.0%)
Required10 (52.6%)
Privileges Required
Low10 (52.6%)
High5 (26.3%)
None4 (21.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32888HIGH Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Versions contain an SQL Injection in the Items search functionality. | Mar 20, 2026 | 8.8 | 30 | NO | NO |
CVE-2025-68434HIGH Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, | Dec 17, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-68147HIGH Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, | Dec 17, 2025 | 8.1 | 26 | NO | NO |
CVE-2026-26746HIGH OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulat | Feb 20, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-63800HIGH The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authent | Nov 18, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-66921HIGH A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via th | Dec 17, 2025 | 7.2 | 24 | NO | NO |
CVE-2022-34578HIGH Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page. | Jul 28, 2022 | 7.2 | 24 | NO | NO |
CVE-2025-66923HIGH A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the p | Dec 17, 2025 | 7.2 | 23 | NO | NO |
CVE-2026-32712MEDIUM Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exi | Apr 7, 2026 | 5.4 | 22 | NO | NO |
CVE-2026-33730MEDIUM Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Ref | Mar 27, 2026 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Open Source Point Of Sale
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.4.1 | 11 | 6.8 | 0.3% | 0 | 0 |
| 3.3.7 | 1 | 7.2 | 1.1% | 0 | 0 |