๐Ÿ” CVE Alert

CVE-2026-107272

MEDIUM 4.7

Gophish through 0.12.1 XSS via Unescaped SMTP Server Error Messages

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling or intercepting a sending profile's SMTP server can execute script when administrators view campaign results or send test emails, stealing API keys.

CWE CWE-79
Vendor gophish
Product gophish
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for gophish gophish

Be the first to know when new medium vulnerabilities affecting gophish gophish are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

gophish / gophish
0 โ‰ค 0.12.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
blog.ostorlab.co: https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.html github.com: https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/static/js/src/app/campaign_results.js#L422-L427 github.com: https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/static/js/src/app/campaigns.js#L110-L113 github.com: https://github.com/gophish/gophish vulncheck.com: https://www.vulncheck.com/advisories/gophish-through-0.12.1-xss-via-unescaped-smtp-server-error-messages

Credits

Sohaib Harraoui (Ostorlab)