github.com
https://github.com/star7th/showdoc CVE-2025-0520
CRITICAL
ShowDoc < 2.8.7 Unauthenticated File Upload Remote Code Execution
Record summary
CVE-2025-0520 has a selected CVSS score of 9.4 (critical).
Description
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 10, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ShowDocBrowse ShowDoc / ShowDocDefault status: unaffected | CVE List, VulnCheck | Before 2.8.7 | affected |
showdoc/showdocBrowse Packagist / showdoc/showdoc | GitHub Advisory | Before 2.8.7 · Fixed in 2.8.7 | affected |
References
6github.comissue tracking
https://github.com/star7th/showdoc/pull/1059 github.comexploit
https://github.com/vulhub/vulhub/tree/master/showdoc/CNVD-2020-26585 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-0520 cnvd.org.cnThird-party advisory
https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/showdoc-unauthenticated-file-upload-rce