gophish has 2 CVEs on record. 1 was published in the last 90 days. The median CVSS is 7.3 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 1
Weakness classes
Products
- github.com/gophish/gophish 1
- gophish 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
gophish vulnerabilities
CVEs affecting gophish, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-82269High· 8.1PoCGophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their ac…
▾ Midnightgophish · gophishEPSS 0.30%via NVD
CVE-2026-39904Medium· 6.5Gophish contains a denial of service vulnerability
Gophish contains a denial of service vulnerability
▾ Sunlitgophish · github.com/gophish/gophishEPSS 0.44%via OSV