CVE-2026-107272: low-severity vulnerability in gophish
Gophish through 0.12.1 XSS via Unescaped SMTP Server Error Messages
Published
25Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 2.3
exploitation probability
—
observed exploitation
nono source reports it
1 public exploit(s)
Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling or intercepting a sending profile's SMTP server can execute script when administrators view campaign results or send test emails, stealing API keys.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
gophish · gophishpublic PoCs found — 1
cve_referenceblog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — gophish
In the same product, most dangerous first.
CVE-2026-39904HIGHGophish 0.12.1 Denial of Service via Office Document UploadEPSS 0.4%CVE-2026-82269HIGHGophish Account Lockout and Forced Password Change Bypassable via API KeyEPSS 0.4%CVE-2026-107273MEDIUMGophish 0.11.0 through 0.12.1 SSRF via POST /api/import/siteEPSS —CVE-2026-107271MEDIUMGophish through 0.12.1 Login Rate Limit Bypass via X-Forwarded-For SpoofingEPSS —CVE-2026-107270HIGHGophish through 0.12.1 Object Takeover via Client-Supplied ID on API Create EndpointsEPSS —CVE-2026-107269MEDIUMGophish through 0.12.1 Username Enumeration via POST /login Timing DiscrepancyEPSS —
References
https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.htmlhttps://github.com/gophish/gophishhttps://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/static/js/src/app/campaign_results.js#L422-L427https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe6/static/js/src/app/campaigns.js#L110-L113https://www.vulncheck.com/advisories/gophish-through-0.12.1-xss-via-unescaped-smtp-server-error-messages