Getgophish
Getgophish Gophish: vulnerabilidades y CVE
Getgophish Gophish tiene 16 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82269 | Alta (8.6) | 0.38% | — | 28 ago 2026 | Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access… |
| CVE-2026-39904 | Alta (7.1) | 0.44% | — | 22 jun 2026 | Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The… |
| CVE-2025-70963 | Alta (7.6) | 0.31% | — | 6 feb 2026 | Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes… |
| CVE-2024-55196 | Alta (7.5) | 0.37% | — | 19 dic 2024 | Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers. |
| CVE-2024-2211 | Media (6.1) | 0.29% | — | 6 mar 2024 | Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu and trigger the payload when the… |
| CVE-2022-45004 | Media (6.1) | 0.60% | — | 22 mar 2023 | Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page. |
| CVE-2022-45003 | Alta (7.5) | 1.0% | — | 22 mar 2023 | Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus. |
| CVE-2022-25295 | Media (5.4) | 0.69% | — | 11 sept 2022 | This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually… |
| CVE-2020-24713 | Alta (7.5) | 1.2% | — | 28 oct 2020 | Gophish through 0.10.1 does not invalidate the gophish cookie upon logout. |
| CVE-2020-24712 | Media (5.4) | 0.86% | — | 28 oct 2020 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page. |
| CVE-2020-24711 | Media (6.5) | 1.6% | — | 28 oct 2020 | The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack |
| CVE-2020-24710 | Media (5.3) | 1.3% | — | 28 oct 2020 | Gophish before 0.11.0 allows SSRF attacks. |
| CVE-2020-24709 | Media (5.4) | 0.56% | — | 28 oct 2020 | Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template. |
| CVE-2020-24708 | Media (5.4) | 0.63% | — | 28 oct 2020 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form. |
| CVE-2020-24707 | Alta (7.8) | 1.3% | — | 28 oct 2020 | Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content. |
| CVE-2019-16146 | Media (4.8) | 0.66% | — | 9 sept 2019 | Gophish through 0.8.0 allows XSS via a username. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.