CVE-2025-0520: Showdoc
Critical severity, CVSS 9.4. EPSS: 2.6% chance of exploitation in the next 30 days.
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
Affected products
- Showdoc Showdoc: before 2.8.7 (fixed in 2.8.7)
Published 2025-04-29. Last modified 2026-10-08.