CVE-2025-0520

Published Apr 29, 2025

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-0520 describes an unrestricted file upload vulnerability found in ShowDoc, an open-source documentation tool. This flaw stems from inadequate validation of file extensions during the upload process. The vulnerability, categorized under CWE-434 (Unrestricted Upload of File with Dangerous Type), allows an attacker to upload and execute arbitrary PHP files on the server. This can lead to remote code execution (RCE) on the affected system. ShowDoc versions prior to 2.8.7 are impacted by this issue.

Description
An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
Source
disclosure@vulncheck.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.4
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

disclosure@vulncheck.com
CWE-434

Social media

Hype score
Not currently trending
  1. Stop scrolling if you use ShowDoc ⚠️ A critical flaw (CVE-2025-0520, 9.4/10) lets hackers upload malicious files with no checks—risking server takeover, data theft, and ransomware. Avoid unverified files & update ASAP. #CyberSecurity #DataBreach #InfoSec

    @TheCyberse46292

    27 Apr 2026

    216 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #ShowDoc #RCE #Flaw CVE-2025-0520 #ActivelyExploited on #Unpatched #Servers https://t.co/2f8P4WaGP5

    @miguelcarvajalm

    20 Apr 2026

    90 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ShowDocにおける5年物の脆弱性悪用されている。CVE-2025-0520はCVSSスコア9.4の任意ファイルアップロード。ウェブシェルのアップロードが観測されている。脆弱性は2020年10月に修正。 https://t.co/XWa9k0b8Mq

    @__kokumoto

    19 Apr 2026

    846 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Hackers are exploiting a 5-year-old ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. https://t.co/ktyXVwG33s

    @TechNowPulse

    19 Apr 2026

    184 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Hackers are exploiting a 5-year-old ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. https://t.co/ktyXVwG33s

    @TechNowPulse

    18 Apr 2026

    189 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 ShowDoc vulnerability patched in 2020 now exploited for server takeovers Unauth file upload (CVE-2025-0520) → web shell + RCE + attacker foothold 💡 Lesson: Unpatched edge services become long-term entry points ⚠️ Action: Patch immediately, hunt web shells, reduce

    @VivekIntel

    18 Apr 2026

    348 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🔍 𝐒𝐡𝐨𝐰𝐃𝐨𝐜 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐲 𝐏𝐚𝐭𝐜𝐡𝐞𝐝 𝐢𝐧 𝟐𝟎𝟐𝟎 𝐍𝐨𝐰 𝐔𝐬𝐞𝐝 𝐢𝐧 𝐀𝐜𝐭𝐢𝐯𝐞 𝐒𝐞𝐫𝐯𝐞𝐫 𝐓𝐚𝐤𝐞𝐨𝐯𝐞𝐫𝐬 • Hacker

    @PurpleOps_io

    18 Apr 2026

    200 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 📢⚠️ Hackers are exploiting a 5-year-old #ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. Read: https://t.co/auBsgiIQ3h #CyberSecurity #Vulnerability #CyberAttacks

    @HackRead

    18 Apr 2026

    1377 Impressions

    6 Retweets

    19 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  9. Active exploits target CVE-2025-0520 (CVSS 9.4) in ShowDoc, a China-based doc collaboration tool. It stems from unsafe file uploads due to poor validation. Stay updated! https://t.co/K0RQmRuSEs

    @technoholic_me

    17 Apr 2026

    169 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. • #CyberSecurity #CyberCrime #DataHack #DataPrivacy #DataTheft #DataLeaks #DataBreach 💾 • • #Hacked #Malware #Spyware #Zerodays #Ransomware #Phishing #Backdoor #RCE #RAT ☠️ • » ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/Y

    @tatha_gautama

    17 Apr 2026

    189 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    4 Replies

    0 Quotes

  11. CVE-2025-0520 (ShowDoc file upload bug) is now being exploited. VulnCheck’s Canary Intelligence spotted first activity, with Caitlin Condon sharing early details and @TheHackersNews covering it. Full story: https://t.co/1js6MbqzJE

    @VulnCheckAI

    17 Apr 2026

    268 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2025-0520, a critical #security #vulnerability impacting #ShowDoc has come under active exploitation in the wild. #CyberSecurity #InfoSec #Cybercrime https://t.co/YXBd7U2THe https://t.co/THrKr4OBG1

    @twelvesec

    17 Apr 2026

    175 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🔒 #CyberSecurity CVE-2025-0520: ShowDoc Critical RCE Exploited in the Wild — Detection and Respo… "Active exploitation of CVE-2025-0520 targets ShowDoc servers. Immediate patching and…" 🔗 https://t.co/XnJBFKwYVU #CyberSecurity #ThreatIntel #cve #zeroday #patchtues

    @SecurityAr58409

    16 Apr 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 Critical ShowDoc RCE Flaw Under Active Attack: #CVE-2025-0520 (CVSS 94) – Patch Now or Get Hacked + Video https://t.co/ihI6ATrLSY Educational Purposes!

    @UndercodeUpdate

    15 Apr 2026

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/Hciv8pd7vQ via @TheHackersNews

    @DCICyberSecNews

    15 Apr 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 ShowDoc Critical Flaw Under Active Attack! A critical unrestricted file upload vulnerability in ShowDoc is being actively exploited in the wild, despite a patch being available since October 2020. 🔴 CVE-2025-0520 CVSS 9.4 The flaw allows unauthenticated attackers to up

    @cytexsmb

    15 Apr 2026

    154 Impressions

    1 Retweet

    3 Likes

    1 Bookmark

    1 Reply

    2 Quotes

  17. Attackers target unpatched ShowDoc servers via CVE-2025-0520 https://t.co/6Kr6vgLc3j

    @CwealthSentinel

    15 Apr 2026

    92 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨 ShowDoc flaw under active exploitation CVE-2025-0520 is a critical RCE vulnerability caused by unrestricted file upload in ShowDoc < 2.8.7. Attackers can upload a malicious PHP file 🔗 https://t.co/WC8SWyQob5 #CyberSecurity #ShowDoc #CVE20250520 #Vulert

    @vulert_official

    15 Apr 2026

    98 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. ⚠️⚠️ CVE-2025-0520 (CVSS 9.4): Old ShowDoc file-upload bug is back in active exploitation and may lead to PHP web-shell RCE. 🔗FOFA Link: https://t.co/XSTI5LD11C 🎯7.6K+ Results are found on https://t.co/NBEEGu7ePJ in the past year. FOFA Query: app="ShowDoc" 🔖Refer

    @fofabot

    15 Apr 2026

    1679 Impressions

    14 Retweets

    19 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  20. ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/VGblFB4p3n via @TheHackersNews

    @jackgoesvirtual

    15 Apr 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. #ShowDoc RCE #Flaw #CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/Wls7bTvut5

    @ScyScan

    15 Apr 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 攻撃者はCVE-2025-0520の脆弱性を悪用し、パッチが適用されていないShowDocサーバーを標的にしている Attackers target unpatched ShowDoc servers via CVE-2025-0520 #SecurityAffairs (Apr 14) https://t.co/OWNrSNabI0

    @foxbook

    14 Apr 2026

    281 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. ShowDocのRCE脆弱性CVE-2025-0520が、パッチ未適用サーバーで積極的に悪用されている ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers #HackerNews (Apr 14) https://t.co/cKAB4rFA8P

    @foxbook

    14 Apr 2026

    223 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Attackers target unpatched ShowDoc servers via CVE-2025-0520 - https://t.co/ardUK7GYat

    @Whitehead4Jeff

    14 Apr 2026

    74 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. #ShowDoc #RCE #Vulnerabilities #Flaw CVE-2025-0520 Actively #Exploited on #Unpatched_Servers https://t.co/H8HhOwr8IS https://t.co/0YjqxNqiUI

    @omvapt

    14 Apr 2026

    90 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. CVE-2025-0520 exploits unrestricted file uploads in ShowDoc, with a 9.4 CVSS score, are you patching your servers before it's too late? Source: ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers #ShowDocVulnerability #RCEFlaw #Cybersecurity https://t.co/S7W

    @Soemailsecurity

    14 Apr 2026

    86 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  27. ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/JD6O9R2FbT

    @Tech_Newsletter

    14 Apr 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. TRC analysis shows attackers exploiting CVE-2025-0520 in unpatched ShowDoc servers to upload PHP web shells and establish persistent access. Post-compromise lateral movement through internal networks demonstrates the importance of runtime segmentation to limit blast radius.

    @aviatrixtrc

    14 Apr 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. ShowDoc #RCE #flaw #CVE-2025-0520 Actively #exploited on Un#patched Servers. Protect your machine against #exploits, update your software with #UCheck https://t.co/wfeUS4Am4f

    @AdliceSoftware

    14 Apr 2026

    105 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 【Attackers target unpatched ShowDoc servers via CVE-2025-0520】 ShowDocの重大RCE「CVE-2025-0520」が、未修正サーバーで実際に悪用されているとの報道。 認証不要のファイルアップロード不備により、外部公開された脆弱環境

    @01ra66it

    14 Apr 2026

    268 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/3ROzmcWEQn via @TheHackersNews

    @ABabino

    14 Apr 2026

    101 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. BREAKING: Critical RCE CVE-2025-0520 in ShowDoc (CVSS 9.4) is under active exploitation, with attackers hitting unpatched servers to run arbitrary code remotely. https://t.co/cCiAlcftjx

    @threatcluster

    14 Apr 2026

    100 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Attackers target unpatched ShowDoc servers via CVE-2025-0520 - https://t.co/Hhj2MZHmFD

    @moton

    14 Apr 2026

    114 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 Critical ShowDoc Vulnerability #CVE-2025-0520 Actively Exploited, Thousands of Servers at Risk + Video -Fact Checker: ✅: 2 ❌: 1 || 2/3 https://t.co/bDwRp2Bmsx

    @UndercodeNews

    14 Apr 2026

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. You updated your systems right? Because attackers are already inside the ones that didn’t. A critical flaw in ShowDoc (CVE-2025-0520) is now being actively exploited, putting unpatched servers at serious risk. #cybersecuritynews Full Story 👉 https://t.co/poJVQFPDwd https://t

    @CSec88

    14 Apr 2026

    131 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Attackers target unpatched ShowDoc servers via CVE-2025-0520 https://t.co/TH5d10baro

    @hackplayers

    14 Apr 2026

    351 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Apr 14, 2026 🚨 A critical RCE vulnerability (CVE-2025-0520) in ShowDoc is being actively exploited on unpatched servers. With a CVSS score of 9.4, immediate updates are essential to protect your data. https://t.co/TznO90CjZo

    @kernyx64

    14 Apr 2026

    119 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. [Security Affairs] Attackers target unpatched ShowDoc servers via CVE-2025-0520. A critical RCE flaw, tracked as CVE-2025-0520, in ShowDoc is being actively exploited, putting unpatched servers at serious risk. A critical remote code execution flaw,... https://t.co/We8uoLlrlj

    @shah_sheikh

    14 Apr 2026

    122 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Attackers target unpatched ShowDoc servers via CVE-2025-0520: A critical RCE flaw, tracked as CVE-2025-0520, in ShowDoc is being actively exploited, putting unpatched servers at serious risk. A critical remote code execution flaw, tracked as… https://t.co/paTdoIX8J4 https://t.c

    @shah_sheikh

    14 Apr 2026

    120 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Attackers target unpatched #ShowDoc servers via CVE-2025-0520 https://t.co/pz3jr1wv64 #securityaffairs #hacking

    @securityaffairs

    14 Apr 2026

    207 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 🚨 ShowDoc RCE vulnerability actively exploited (CVE-2025-0520) Unrestricted file upload → web shell deployment + full server compromise Lesson: Old bugs don’t die — they wait. If you’re running unpatched apps, you’re already a target https://t.co/mwvuYJRwne

    @VivekIntel

    14 Apr 2026

    166 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. iT4iNT SERVER ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/HxyYx3LJ7s VDS VPS Cloud #ShowDoc #CVE20250520 #CyberSecurity #InfoSec #Vulnerability

    @it4int

    14 Apr 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. ==== 👁️ ==== Security Alert 🔐 ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers A critical security... https://t.co/9nwZDQWB5L ID: 0e9a1cd652c8 #CyberAttack #InfoSec #DataBreach ================

    @MonstersRunAll

    14 Apr 2026

    130 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/VENDNpoa7d

    @Dinosn

    14 Apr 2026

    1194 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  45. ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited https://t.co/Ha0oNjgzVH https://t.co/MjPi4BICtZ

    @devsecopscv

    14 Apr 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Critical RCE flaw CVE-2025-0520 in ShowDoc allows attackers to upload malicious PHP files and execute code remotely. Affects versions before 2.8.7; fixed in Oct 2020 update. Exploited on unpatched servers. #ShowDoc #RemoteCode #China https://t.co/SFx29rVVM0

    @TweetThreatNews

    14 Apr 2026

    180 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. 🚨 #CVE-2025-0520: Unauthenticated Web Shell Uploads Exploited in the Wild – Patch Now! + Video https://t.co/oQ2JEriLbo Educational Purposes!

    @UndercodeUpdate

    14 Apr 2026

    100 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 🚨 A ShowDoc flaw (CVSS 9.4) is now under active exploitation. CVE-2025-0520 lets attackers upload web shells via unauthenticated file upload → full server control. First attacks seen via a U.S. honeypot; ~2,000 instances remain exposed, mostly in China. https://t.co/mmYGbP9

    @GlitchWolf_0609

    14 Apr 2026

    112 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  49. ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers: A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The… https://t.co/otPUALWc0e https://

    @shah_sheikh

    14 Apr 2026

    115 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/SIud78yEX7

    @TheCyberSecHub

    14 Apr 2026

    625 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes