{"id":"CVE-2025-0520","aliases":["GHSA-6jmr-r7p6-f5wr"],"url":"https://o3.security/vulnerability/CVE-2025-0520","summary":"ShowDoc < 2.8.7 Unauthenticated File Upload Remote Code Execution","details":"An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.","published":"2025-04-29T19:35:37.829Z","modified":"2026-08-08T03:48:09.284964517Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"showdoc/showdoc","fixedVersion":"2.8.7"}],"fix":{"url":"https://github.com/star7th/showdoc/pull/1059","label":"star7th/showdoc#1059"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0520.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0520"},{"type":"ADVISORY","url":"https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/showdoc-unauthenticated-file-upload-rce"},{"type":"REPORT","url":"https://github.com/star7th/showdoc/pull/1059"},{"type":"EVIDENCE","url":"https://github.com/vulhub/vulhub/tree/master/showdoc/CNVD-2020-26585"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:09.284964517Z"}}