CVE-2025-0520

ShowDoc < 2.8.7 Unauthenticated File Upload Remote Code Execution

Basic Information

CVE State
PUBLISHED
Reserved Date
January 16, 2025
Published Date
April 29, 2025
Last Updated
November 19, 2025
Vendor
ShowDoc
Product
ShowDoc
Description
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

CVSS Scores

CVSS v4.0

9.4 - CRITICAL

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

SSVC Information

Exploitation
poc
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-04-16 18:40:07 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2026-04-16 18:40:07 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel