CVE-2023-5965: Espocrm

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

An authenticated privileged attacker could upload a specially crafted zip to the EspoCRM server in version 7.2.5, via the update form, which could lead to arbitrary PHP code execution.

Affected products

  • Espocrm Espocrm: up to and including 7.5.2

Published 2023-11-30. Last modified 2026-06-17.