ShowDoc Vulnerability Patched in 2020 Now Used in Active Server Takeovers
ID: 837ca997-fe9e-52cd-8dc2-3a519eba8fb0
STIX ID: report--837ca997-fe9e-52cd-8dc2-3a519eba8fb0
Feed Name: HackRead
Threat Score
**ShowDoc CVE-2025-0520 (CVSS 9.4):** An unrestricted file upload vulnerability in ShowDoc allows unauthenticated attackers to upload PHP web shells and obtain remote code execution; active exploitation has been observed (a webshell dropped on a U.S. canary) and there are 2,000+ publicly visible instances, so affected users should upgrade to the patched releases (>=2.8.7; recommended 3.8.1).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
