Netgsm is a narrowly scoped SMS and messaging platform with a focused product footprint, centered on its core communication service. The observed vulnerability signal reflects access-control and authorization issues that are characteristic of web-facing communication APIs where improper permission boundaries can expose user data or enable lateral account access. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netgsm over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68010HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in netgsm Netgsm netgsm allows Reflected XSS.This issue affects Netgsm: from n/a | Jan 22, 2026 | 7.1 | 27 | NO | NO |
CVE-2024-35672CRITICAL Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19. | Jun 4, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-4746MEDIUM Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through <= 2 | Jun 10, 2024 | 6.3 | 19 | NO | NO |
CVE-2024-32544HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Netgsm allows Reflected XSS.This issue affects Netgsm: from n/a through 2.8. | Apr 17, 2024 | 7.1 | 19 | NO | NO |
CVE-2025-60143MEDIUM Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netgsm: from n/a through <= 2 | Sep 26, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netgsm.
Media articles that mention a CVE ID that affects a product developed by Netgsm — matched by CVE ID, not by vendor name.