CVE-2025-70963
Published Feb 6, 2026Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the rendered HTML/JavaScript of the…
- evidence mentions
- 1
- Buzz score
- 16.4