« Volver al listado

Getgophish

Getgophish Gophish: vulnerabilidades y CVE

Getgophish Gophish tiene 16 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses3
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-82269Alta (8.6)0.38%—28 ago 2026
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access…
CVE-2026-39904Alta (7.1)0.44%—22 jun 2026
Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The…
CVE-2025-70963Alta (7.6)0.31%—6 feb 2026
Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes…
CVE-2024-55196Alta (7.5)0.37%—19 dic 2024
Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.
CVE-2024-2211Media (6.1)0.29%—6 mar 2024
Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu and trigger the payload when the…
CVE-2022-45004Media (6.1)0.60%—22 mar 2023
Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.
CVE-2022-45003Alta (7.5)1.0%—22 mar 2023
Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.
CVE-2022-25295Media (5.4)0.69%—11 sept 2022
This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually…
CVE-2020-24713Alta (7.5)1.2%—28 oct 2020
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
CVE-2020-24712Media (5.4)0.86%—28 oct 2020
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
CVE-2020-24711Media (6.5)1.6%—28 oct 2020
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack
CVE-2020-24710Media (5.3)1.3%—28 oct 2020
Gophish before 0.11.0 allows SSRF attacks.
CVE-2020-24709Media (5.4)0.56%—28 oct 2020
Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.
CVE-2020-24708Media (5.4)0.63%—28 oct 2020
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
CVE-2020-24707Alta (7.8)1.3%—28 oct 2020
Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
CVE-2019-16146Media (4.8)0.66%—9 sept 2019
Gophish through 0.8.0 allows XSS via a username.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services2
  2. T1078 Valid Accounts1
  3. T1190 Exploit Public-Facing Application1
  4. T1203 Exploitation for Client Execution1
  5. T1499 Endpoint Denial of Service1
  6. T1552 Unsecured Credentials1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.