VendorsGetgophishgophishany version
Vulnerabilities

Getgophish Gophish any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2020-24707
Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
Published 2020-10-28 · Modified
9.3EPSS 0.013
CVE-2025-70963
Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.
Published 2026-02-06 · Analyzed
7.6EPSS 0.003
CVE-2020-24713
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
Published 2020-10-28 · Modified
7.5EPSS 0.012
CVE-2022-45003
Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.
Published 2023-03-22 · Modified
7.5EPSS 0.010
CVE-2020-24711
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack
Published 2020-10-28 · Modified
6.5EPSS 0.016
CVE-2022-45004
Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.
Published 2023-03-22 · Modified
6.1EPSS 0.006
CVE-2020-24712
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
Published 2020-10-28 · Modified
5.4EPSS 0.009
CVE-2022-25295
Open Redirect
Published 2022-09-11 · Modified
5.4EPSS 0.007
CVE-2020-24708
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
Published 2020-10-28 · Modified
5.4EPSS 0.006
CVE-2020-24709
Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.
Published 2020-10-28 · Modified
5.4EPSS 0.006
CVE-2020-24710
Gophish before 0.11.0 allows SSRF attacks.
Published 2020-10-28 · Modified
5.3EPSS 0.013
CVE-2019-16146
Gophish through 0.8.0 allows XSS via a username.
Published 2019-09-09 · Modified
4.8EPSS 0.007