CVE-2020-24712: Getgophish Gophish

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.

Affected products

  • Getgophish Gophish: before 0.11.0 (fixed in 0.11.0)

Published 2020-10-28. Last modified 2026-06-17.