Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gophish HIGH 7.6
CVE-2025-70963

Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the r…

Fix: after 0.12.1
Fix from $1,950 2026-02-06
Gophish MEDIUM 6.1
CVE-2024-2211

Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaSc…

Mitigation only
Fix from $1,600 2024-03-06
Gophish MEDIUM 6.1
CVE-2022-45004

Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.

Fix: after 0.12.1
Fix from $1,600 2023-03-22
Gophish HIGH 7.5
CVE-2022-45003

Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.

Fix: after 0.12.1
Fix from $1,950 2023-03-22
Gophish MEDIUM 5.4
CVE-2022-25295

This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The applicatio…

Fix: 0.12.0+
Fix from $1,600 2022-09-11
Gophish HIGH 7.8
CVE-2020-24707

Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.

Fix: 0.11.0+
Fix from $1,950 2020-10-28
Gophish HIGH 7.5
CVE-2020-24713

Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.

Fix: after 0.10.1
Fix from $1,950 2020-10-28
Gophish MEDIUM 6.5
CVE-2020-24711

The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack

Fix: 0.11.0+
Fix from $1,600 2020-10-28
Gophish MEDIUM 5.4
CVE-2020-24708

Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.

Fix: 0.11.0+
Fix from $1,600 2020-10-28
Gophish MEDIUM 5.4
CVE-2020-24709

Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.

Fix: after 0.10.1
Fix from $1,600 2020-10-28
Gophish MEDIUM 5.4
CVE-2020-24712

Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.

Fix: 0.11.0+
Fix from $1,600 2020-10-28
Gophish MEDIUM 5.3
CVE-2020-24710

Gophish before 0.11.0 allows SSRF attacks.

Fix: 0.11.0+
Fix from $1,600 2020-10-28