Vulnerabilities > Getgophish > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-03-22 CVE-2022-45004 Cross-site Scripting vulnerability in Getgophish Gophish
Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.
network
low complexity
getgophish CWE-79
6.1
2022-09-11 CVE-2022-25295 Open Redirect vulnerability in Getgophish Gophish
This affects the package github.com/gophish/gophish before 0.12.0.
network
low complexity
getgophish CWE-601
5.4
2020-10-28 CVE-2020-24712 Cross-site Scripting vulnerability in Getgophish Gophish
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
network
low complexity
getgophish CWE-79
5.4
2020-10-28 CVE-2020-24711 Improper Restriction of Rendered UI Layers or Frames vulnerability in Getgophish Gophish
The Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attack
network
low complexity
getgophish CWE-1021
6.5
2020-10-28 CVE-2020-24710 Server-Side Request Forgery (SSRF) vulnerability in Getgophish Gophish
Gophish before 0.11.0 allows SSRF attacks.
network
low complexity
getgophish CWE-918
5.3
2020-10-28 CVE-2020-24709 Cross-site Scripting vulnerability in Getgophish Gophish
Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.
network
low complexity
getgophish CWE-79
5.4
2020-10-28 CVE-2020-24708 Cross-site Scripting vulnerability in Getgophish Gophish
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
network
low complexity
getgophish CWE-79
5.4
2019-09-09 CVE-2019-16146 Cross-site Scripting vulnerability in Getgophish Gophish
Gophish through 0.8.0 allows XSS via a username.
network
low complexity
getgophish CWE-79
4.8