{"id":"CVE-2025-0520","title":"An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.","summary":"An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.","severity":"critical","cvss":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L","cwe":["CWE-434"],"vendor":"ShowDoc","product":"ShowDoc","affected":["ShowDoc < 2.8.7"],"published":"2025-04-29","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:16:50.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-0520","references":[{"url":"https://github.com/star7th/showdoc/pull/1059","label":"disclosure@vulncheck.com"},{"url":"https://github.com/vulhub/vulhub/tree/master/showdoc/CNVD-2020-26585","label":"disclosure@vulncheck.com"},{"url":"https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/showdoc-unauthenticated-file-upload-rce","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2025-04-29T20:38:44.727309Z"},"cvssSource":"cna","epss":0.02647,"epssPercentile":0.85159,"exploits":{"nuclei":["CVE-2025-0520"],"checkedAt":"2026-10-08T16:52:49.753Z"},"ingestedAt":"2026-10-08T16:52:14.662Z","slug":"CVE-2025-0520","body":"## Overview\n\nAn unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":64,"depthScoreParts":{"impact":51.7,"likelihood":0.5,"exploitation":12,"ransomware":0},"changes":[]}