Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107272

MEDIUM NVD
CVSS Score 4.7
Severity MEDIUM
Published Oct 07, 2026
Vendor unknown

Description

Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling or intercepting a sending profile's SMTP server can execute script when administrators view campaign results or send test emails, stealing API keys.

References