Cozyvision
Cozyvision SMS Alert Order Notifications: vulnerabilities and CVEs
Cozyvision SMS Alert Order Notifications has 17 published vulnerabilities, 7 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.
CVEs17
Last 12 months7
Critical5
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-95594 | High (8.1) | — | — | Oct 6, 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions. |
| CVE-2026-66424 | Critical (9.8) | 0.48% | — | Aug 13, 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. |
| CVE-2026-59540 | Critical (9.8) | 0.48% | — | Jul 23, 2026 | Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. |
| CVE-2026-54802 | High (7.5) | 0.48% | — | Jun 17, 2026 | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. |
| CVE-2026-32373 | Medium (5.4) | 0.29% | — | Mar 13, 2026 | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from… |
| CVE-2025-66086 | Medium (5.3) | 0.21% | — | Nov 21, 2025 | Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from… |
| CVE-2025-49915 | Critical (9.3) | 0.49% | — | Oct 22, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order… |
| CVE-2025-47682 | Critical (9.8) | 0.38% | — | May 12, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order… |
| CVE-2025-3878 | Medium (5.4) | 0.27% | — | May 10, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_verify shortcode in all versions up to, and including, 3.8.1 due to insufficient… |
| CVE-2025-3876 | High (8.8) | 0.44% | — | May 10, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAction() function in all versions up to,… |
| CVE-2024-13553 | Critical (9.8) | 0.54% | — | Apr 1, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host… |
| CVE-2025-26988 | High (7.5) | 0.52% | — | Mar 3, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS Alert Order… |
| CVE-2025-26984 | Medium (6.1) | 0.33% | — | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Reflected XSS.This issue affects SMS Alert Order… |
| CVE-2024-11725 | High (8.8) | 0.51% | — | Jan 7, 2025 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the… |
| CVE-2024-10233 | Medium (5.4) | 0.34% | — | Oct 29, 2024 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient… |
| CVE-2024-1489 | Medium (4.3) | 0.24% | — | Mar 13, 2024 | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.9. This is due to missing or incorrect nonce validation on the… |
| CVE-2021-24588 | Medium (6.1) | 0.83% | — | Sep 6, 2021 | The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.