Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Gophish
(Getgophish)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 12 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2023-03-22 | CVE-2022-45004 | Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page. | Gophish | 6.1 | ||
2024-03-06 | CVE-2024-2211 | Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu and trigger the payload when the campaign is removed from the menu. | Gophish | 6.1 | ||
2023-03-22 | CVE-2022-45003 | Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus. | Gophish | 7.5 | ||
2020-10-28 | CVE-2020-24707 | Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content. | Gophish | 7.8 | ||
2020-10-28 | CVE-2020-24708 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form. | Gophish | 5.4 | ||
2020-10-28 | CVE-2020-24709 | Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template. | Gophish | 5.4 | ||
2020-10-28 | CVE-2020-24710 | Gophish before 0.11.0 allows SSRF attacks. | Gophish | 5.3 | ||
2020-10-28 | CVE-2020-24711 | The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack | Gophish | 6.5 | ||
2020-10-28 | CVE-2020-24712 | Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page. | Gophish | 5.4 | ||
2020-10-28 | CVE-2020-24713 | Gophish through 0.10.1 does not invalidate the gophish cookie upon logout. | Gophish | 7.5 |