VulnSea

gophish vulnerabilities

CVEs whose affected-version data names the gophish package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-107273Medium· 4.3
today

Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site

Gophish 0.11.0 through 0.12.1 contains a server-side request forgery vulnerability that allows authenticated low-privileged users to reach loopback and private hosts via POST /api/import/site. Attackers can submit internal URLs, which th…

▾ Sunlitgophish · gophishvia NVD
CVE-2026-107272Medium· 4.7PoC
today

Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages

Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling or intercepting a sending profile's …

▾ Twilightgophish · gophishvia NVD
CVE-2026-107271Medium· 5.3
today

Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers

Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers. Attackers can send a different forwarded address per req…

▾ Sunlitgophish · gophishvia NVD
CVE-2026-107270High· 7.1PoC
today

Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles

Gophish through 0.12.1 contains an insecure direct object reference vulnerability that allows authenticated users to take over other users' groups, templates, landing pages and sending profiles. Attackers can supply another user's sequen…

▾ Midnightgophish · gophishvia NVD
CVE-2026-107269Low· 3.7
today

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times

Gophish through 0.12.1 contains a timing discrepancy vulnerability in AdminServer.Login that allows unauthenticated attackers to enumerate valid usernames by measuring login response times. Attackers can submit candidate usernames to POS…

▾ Sunlitgophish · gophishvia NVD
CVE-2026-82269High· 8.1PoC
1mo ago

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware

Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their ac…

▾ Midnightgophish · gophishEPSS 0.38%via NVD
gophish vulnerabilities (CVEs) · VulnSea