logo

Attackers target unpatched ShowDoc servers via CVE-2025-0520

ID: f8511284-70e8-5faf-86a7-af0f780c7af2

STIX ID: report--f8511284-70e8-5faf-86a7-af0f780c7af2

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical unauthenticated file upload vulnerability (CVE-2025-0520, CVSS 9.4) in ShowDoc (versions before 2.8.7) permits attackers to upload arbitrary PHP files and achieve remote code execution; the flaw was patched in 2.8.7 (Oct 2020) but is being actively exploited in the wild against thousands of unpatched instances, enabling web shells and potential full server compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.