Getgophish

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    10
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-82269

    Gophish Account Lockout and Forced Password Change Bypassable via API Key

    Last Modified: Aug 28, 2026
    Published: Aug 28, 2026

    CVE-2026-39904

    Gophish 0.12.1 Denial of Service via Office Document Upload

    Last Modified: Jul 14, 2026
    Published: Jun 22, 2026

    CVE-2025-70963

    Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the page on every login. This makes permanent API credentials accessible to any script running in the browser context.

    Last Modified: Feb 10, 2026
    Published: Feb 06, 2026

    CVE-2024-2211

    Cross-Site Scripting vulnerability in Gophish Admin Panel

    Last Modified: Feb 26, 2025
    Published: Mar 06, 2024

    CVE-2022-45003

    Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.

    Last Modified: Feb 25, 2025
    Published: Mar 22, 2023
    Items Per Page
    Getgophish Vulnerabilities & Security CVEs | CVE-DB