Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Orpak

First CVE: Jun 3, 2019Active for: 7 yearsTotal CVEs: 6

Orpak develops the Siteomat product line, a modestly represented set of web-based retail and point-of-sale management solutions. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate on web application and data-handling weaknesses including code injection, cross-site scripting, SQL injection, buffer overflows, and missing encryption of sensitive data—classic vectors for compromising customer transaction data and operational continuity in retail environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
6.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
9.2
Avg CVSS Score
Higher Avg CVSS Score than 88% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Orpak over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 3, 2019
7 years ago
Most Recent CVE
Jun 3, 2019
2,608 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-14854CRITICAL
A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vulnerability affects all versions prior to 2017-09-25.
Jun 3, 20199.834NONO
CVE-2017-14853CRITICAL
The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with t
Jun 3, 20199.833NONO
CVE-2017-14728CRITICAL
An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOm
Jun 3, 20199.832NONO
CVE-2017-14851CRITICAL
A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contain
Jun 3, 20199.831NONO
CVE-2017-14852CRITICAL
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eav
Jun 3, 20199.829NONO
CVE-2017-14850MEDIUM
All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. A
Jun 3, 20196.121NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
17%
83%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Orpak.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Orpak — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Orpak's Products

View all 1 CNAs →

Top CWEs