getgophish CVE Vulnerabilities & CVE List (13)

Products (CPE): — CVEs: 13

getgophish vulnerability overview

Aggregates CVE and security vulnerability intelligence across all getgophish-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk ssrf, vendor risk open redirect, and vendor risk path handling and related problems; some flaws may lead to vendor impact session compromise and vendor impact file overwrite.

Vulnerability distribution trend (last 24 months)

Showing 113 of 13 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-70963 Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context. [email protected] 7.6 0.04% 2026-02-06 2026-02-10
CVE-2024-2211 Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu and trigger the payload when the campaign is removed from the menu. [email protected] 4.6 0.08% 2024-03-06 2025-02-26
CVE-2022-45004 Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page. [email protected] 6.1 0.45% 2023-03-22 2025-02-26
CVE-2022-45003 Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus. [email protected] 7.5 0.69% 2023-03-22 2025-02-25
CVE-2022-25295 This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts with multiple backslashes like \\\\\\example.com, browser will redirect user to http://example.com. [email protected] 5.4 0.20% 2022-09-11 2024-11-21
CVE-2020-24713 Gophish through 0.10.1 does not invalidate the gophish cookie upon logout. [email protected] 7.5 0.36% 2020-10-28 2024-11-21
CVE-2020-24712 Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page. [email protected] 5.4 0.36% 2020-10-28 2024-11-21
CVE-2020-24711 The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack [email protected] 6.5 0.49% 2020-10-28 2024-11-21
CVE-2020-24710 Gophish before 0.11.0 allows SSRF attacks. [email protected] 5.3 0.46% 2020-10-28 2024-11-21
CVE-2020-24709 Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template. [email protected] 5.4 0.21% 2020-10-28 2024-11-21
CVE-2020-24708 Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form. [email protected] 5.4 0.28% 2020-10-28 2024-11-21
CVE-2020-24707 Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content. [email protected] 7.8 0.34% 2020-10-28 2024-11-21
CVE-2019-16146 Gophish through 0.8.0 allows XSS via a username. [email protected] 4.8 0.24% 2019-09-09 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence