CVE-2026-107272
LOW
2,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling or intercepting a sending profile's SMTP server can execute script when administrators view campaign results or send test emails, stealing API keys.
79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
StableCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Integrity
Availability
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
AI/ML, Web Based, Web Server
https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.html
https://github.com/gophish/gophish
https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe…
https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe…
https://www.vulncheck.com/advisories/gophish-through-0.12.1-xss-via-unescaped-s…