logo

ShowDoc Vulnerability Patched in 2020 Now Used in Active Server Takeovers

ID: 837ca997-fe9e-52cd-8dc2-3a519eba8fb0

STIX ID: report--837ca997-fe9e-52cd-8dc2-3a519eba8fb0

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-04-18

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**ShowDoc CVE-2025-0520 (CVSS 9.4):** An unrestricted file upload vulnerability in ShowDoc allows unauthenticated attackers to upload PHP web shells and obtain remote code execution; active exploitation has been observed (a webshell dropped on a U.S. canary) and there are 2,000+ publicly visible instances, so affected users should upgrade to the patched releases (>=2.8.7; recommended 3.8.1).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.