CVE-2026-107272: Gophish

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling or intercepting a sending profile's SMTP server can execute script when administrators view campaign results or send test emails, stealing API keys.

Affected products

  • Gophish Gophish: up to and including 0.12.1

Published 2026-10-07. Last modified 2026-10-07.