CVE-2026-107269Low· 3.7▾ SunlitGophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POS…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POST /login and detect bcrypt comparison delays for existing accounts, narrowing targets for password guessing or credential stuffing.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107273Medium· 4.3Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site
CVE-2026-107272Medium· 4.7Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages
CVE-2026-107271Medium· 5.3Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers
CVE-2026-107270High· 7.1Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles
CVE-2026-82269High· 8.1Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware
CVE-2026-39904Medium· 6.5Gophish contains a denial of service vulnerability