CVE-2025-0520
ShowDoc < 2.8.7 Unauthenticated File Upload Remote Code Execution
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
| CWE | CWE-434 |
| Vendor | showdoc |
| Product | showdoc |
| Published | Apr 29, 2025 |
| Last Updated | Jun 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for showdoc showdoc
Be the first to know when new unknown vulnerabilities affecting showdoc showdoc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ShowDoc / ShowDoc
0 < 2.8.7