CVE-2023-5965: Espocrm
High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.
An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.
Affected products
- Espocrm Espocrm: up to and including 7.5.2
Published 2023-11-30. Last modified 2026-06-17.