CVE-2025-0520

CRITICAL EXPLOITED

ShowDoc < 2.8.7 - Unauthenticated Remote Code Execution via File Upload

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-0520 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

References (4)

Core 4
Core References
Issue Tracking patch issue-tracking
https://github.com/star7th/showdoc/pull/1059
Various Sources third-party-advisory
https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585

Scores

CVSS v4 9.4
EPSS 0.0094
EPSS Percentile 56.4%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

VulnCheck KEV 2026-04-10
CWE
CWE-434
Status published
Products (2)
ShowDoc/ShowDoc < 2.8.7
showdoc/showdoc 0 - 2.8.7Packagist
Published Apr 29, 2025
Tracked Since Feb 18, 2026