Cozyvision's vulnerability footprint centers on its SMS alert and order notification platform, a modestly represented but prominent service in the e-commerce and logistics sector. The exposure recurs through application-layer weaknesses including cross-site scripting, SQL injection, missing authorization controls, and authentication bypass vulnerabilities that reflect the web-facing, data-handling nature of the product, while vulnerabilities affecting the vendor skew toward serious outcomes. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cozyvision over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47682CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This | May 12, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-49915CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This | Oct 22, 2025 | 9.3 | 28 | NO | NO |
CVE-2024-13553CRITICAL The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is | Apr 1, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-11725HIGH The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capab | Jan 7, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-26988HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This | Mar 3, 2025 | 7.5 | 23 | NO | NO |
CVE-2025-3876HIGH The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insufficient user OTP validation in the handleWpLoginCreateUserAct | May 10, 2025 | 8.8 | 22 | NO | NO |
CVE-2021-24588MEDIUM The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page. | Sep 6, 2021 | 6.1 | 22 | NO | NO |
CVE-2026-32373MEDIUM Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect | Mar 13, 2026 | 5.4 | 19 | NO | NO |
CVE-2025-26984MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Reflected XSS.This | Mar 3, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-66086MEDIUM Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affect | Nov 21, 2025 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cozyvision.
Media articles that mention a CVE ID that affects a product developed by Cozyvision — matched by CVE ID, not by vendor name.