CVE-2026-107272: Gophish
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling or intercepting a sending profile's SMTP server can execute script when administrators view campaign results or send test emails, stealing API keys.
Affected products
- Gophish Gophish: up to and including 0.12.1
Published 2026-10-07. Last modified 2026-10-07.