Cross-Site Scripting Vulnerabilities in Gophish by Gophish
CVE-2026-107272

2.3LOW

Key Information:

Vendor

Gophish

Status
Vendor
CVE Published:
7 October 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-107272?

Gophish versions up to 0.12.1 are susceptible to both stored and reflected cross-site scripting (XSS) vulnerabilities. These vulnerabilities arise from the improper handling of error messages returned by malicious SMTP servers, which can lead to script injection. Attackers who control or intercept the SMTP server used by Gophish can exploit this flaw when administrators view campaign results or send test emails. This exploitation could result in the unauthorized access to sensitive information, including API keys.

Affected Version(s)

gophish 0 <= 0.12.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sohaib Harraoui (Ostorlab)
.