CVE-2023-24686: Churchcrm

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.

Affected products

  • Churchcrm Churchcrm: up to and including 4.5.3

Published 2023-02-09. Last modified 2026-06-17.