Record summary

CVE-2025-0520 has a selected CVSS score of 9.4 (critical).

Description

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 10, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List, VulnCheckBefore 2.8.7affected
GitHub AdvisoryBefore 2.8.7 · Fixed in 2.8.7affected

References

6