Cozyvision
Cozyvision SMS Alert Order Notifications: vulnerabilidades y CVE
Cozyvision SMS Alert Order Notifications tiene 17 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses7
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-95594 | Alta (8.1) | 0.24% | — | 6 oct 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions. |
| CVE-2026-66424 | Crítica (9.8) | 0.48% | — | 13 ago 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. |
| CVE-2026-59540 | Crítica (9.8) | 0.48% | — | 23 jul 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. |
| CVE-2026-54802 | Alta (7.5) | 0.48% | — | 17 jun 2026 | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. |
| CVE-2026-32373 | Media (5.4) | 0.29% | — | 13 mar 2026 | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from… |
| CVE-2025-66086 | Media (5.3) | 0.21% | — | 21 nov 2025 | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from… |
| CVE-2025-49915 | Crítica (9.3) | 0.49% | — | 22 oct 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order… |
| CVE-2025-47682 | Crítica (9.8) | 0.38% | — | 12 may 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order… |
| CVE-2025-3878 | Media (5.4) | 0.28% | — | 10 may 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient… |
| CVE-2025-3876 | Alta (8.8) | 0.46% | — | 10 may 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to,… |
| CVE-2024-13553 | Crítica (9.8) | 0.54% | — | 1 abr 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host… |
| CVE-2025-26988 | Alta (7.5) | 0.52% | — | 3 mar 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order… |
| CVE-2025-26984 | Media (6.1) | 0.33% | — | 3 mar 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Reflected XSS.This issue affects SMS Alert Order… |
| CVE-2024-11725 | Alta (8.8) | 0.51% | — | 7 ene 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the… |
| CVE-2024-10233 | Media (5.4) | 0.34% | — | 29 oct 2024 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient… |
| CVE-2024-1489 | Media (4.3) | 0.24% | — | 13 mar 2024 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the… |
| CVE-2021-24588 | Media (6.1) | 0.83% | — | 6 sept 2021 | The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.