VYPR
Medium severity4.7NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026

CVE-2026-107272

CVE-2026-107272

Description

Gophish through 0.12.1 contains stored and reflected cross-site scripting vulnerabilities that allow attackers to inject script by returning malicious SMTP server error messages. Attackers controlling or intercepting a sending profile's SMTP server can execute script when administrators view campaign results or send test emails, stealing API keys.

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.