CVE-2023-24686: Churchcrm
Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.
Affected products
- Churchcrm Churchcrm: up to and including 4.5.3
Published 2023-02-09. Last modified 2026-06-17.