AI description
CVE-2025-0520 describes an unrestricted file upload vulnerability found in ShowDoc, an open-source documentation tool. This flaw stems from inadequate validation of file extensions during the upload process. The vulnerability, categorized under CWE-434 (Unrestricted Upload of File with Dangerous Type), allows an attacker to upload and execute arbitrary PHP files on the server. This can lead to remote code execution (RCE) on the affected system. ShowDoc versions prior to 2.8.7 are impacted by this issue.
- Description
- An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
- Source
- disclosure@vulncheck.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- disclosure@vulncheck.com
- CWE-434
- Hype score
- Not currently trending
Stop scrolling if you use ShowDoc ⚠️ A critical flaw (CVE-2025-0520, 9.4/10) lets hackers upload malicious files with no checks—risking server takeover, data theft, and ransomware. Avoid unverified files & update ASAP. #CyberSecurity #DataBreach #InfoSec
@TheCyberse46292
27 Apr 2026
216 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#ShowDoc #RCE #Flaw CVE-2025-0520 #ActivelyExploited on #Unpatched #Servers https://t.co/2f8P4WaGP5
@miguelcarvajalm
20 Apr 2026
90 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ShowDocにおける5年物の脆弱性悪用されている。CVE-2025-0520はCVSSスコア9.4の任意ファイルアップロード。ウェブシェルのアップロードが観測されている。脆弱性は2020年10月に修正。 https://t.co/XWa9k0b8Mq
@__kokumoto
19 Apr 2026
846 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Hackers are exploiting a 5-year-old ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. https://t.co/ktyXVwG33s
@TechNowPulse
19 Apr 2026
184 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Hackers are exploiting a 5-year-old ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. https://t.co/ktyXVwG33s
@TechNowPulse
18 Apr 2026
189 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 ShowDoc vulnerability patched in 2020 now exploited for server takeovers Unauth file upload (CVE-2025-0520) → web shell + RCE + attacker foothold 💡 Lesson: Unpatched edge services become long-term entry points ⚠️ Action: Patch immediately, hunt web shells, reduce
@VivekIntel
18 Apr 2026
348 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔍 𝐒𝐡𝐨𝐰𝐃𝐨𝐜 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐲 𝐏𝐚𝐭𝐜𝐡𝐞𝐝 𝐢𝐧 𝟐𝟎𝟐𝟎 𝐍𝐨𝐰 𝐔𝐬𝐞𝐝 𝐢𝐧 𝐀𝐜𝐭𝐢𝐯𝐞 𝐒𝐞𝐫𝐯𝐞𝐫 𝐓𝐚𝐤𝐞𝐨𝐯𝐞𝐫𝐬 • Hacker
@PurpleOps_io
18 Apr 2026
200 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
📢⚠️ Hackers are exploiting a 5-year-old #ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. Read: https://t.co/auBsgiIQ3h #CyberSecurity #Vulnerability #CyberAttacks
@HackRead
18 Apr 2026
1377 Impressions
6 Retweets
19 Likes
5 Bookmarks
0 Replies
0 Quotes
Active exploits target CVE-2025-0520 (CVSS 9.4) in ShowDoc, a China-based doc collaboration tool. It stems from unsafe file uploads due to poor validation. Stay updated! https://t.co/K0RQmRuSEs
@technoholic_me
17 Apr 2026
169 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
• #CyberSecurity #CyberCrime #DataHack #DataPrivacy #DataTheft #DataLeaks #DataBreach 💾 • • #Hacked #Malware #Spyware #Zerodays #Ransomware #Phishing #Backdoor #RCE #RAT ☠️ • » ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/Y
@tatha_gautama
17 Apr 2026
189 Impressions
0 Retweets
0 Likes
0 Bookmarks
4 Replies
0 Quotes
CVE-2025-0520 (ShowDoc file upload bug) is now being exploited. VulnCheck’s Canary Intelligence spotted first activity, with Caitlin Condon sharing early details and @TheHackersNews covering it. Full story: https://t.co/1js6MbqzJE
@VulnCheckAI
17 Apr 2026
268 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-0520, a critical #security #vulnerability impacting #ShowDoc has come under active exploitation in the wild. #CyberSecurity #InfoSec #Cybercrime https://t.co/YXBd7U2THe https://t.co/THrKr4OBG1
@twelvesec
17 Apr 2026
175 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2025-0520: ShowDoc Critical RCE Exploited in the Wild — Detection and Respo… "Active exploitation of CVE-2025-0520 targets ShowDoc servers. Immediate patching and…" 🔗 https://t.co/XnJBFKwYVU #CyberSecurity #ThreatIntel #cve #zeroday #patchtues
@SecurityAr58409
16 Apr 2026
85 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical ShowDoc RCE Flaw Under Active Attack: #CVE-2025-0520 (CVSS 94) – Patch Now or Get Hacked + Video https://t.co/ihI6ATrLSY Educational Purposes!
@UndercodeUpdate
15 Apr 2026
80 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/Hciv8pd7vQ via @TheHackersNews
@DCICyberSecNews
15 Apr 2026
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 ShowDoc Critical Flaw Under Active Attack! A critical unrestricted file upload vulnerability in ShowDoc is being actively exploited in the wild, despite a patch being available since October 2020. 🔴 CVE-2025-0520 CVSS 9.4 The flaw allows unauthenticated attackers to up
@cytexsmb
15 Apr 2026
154 Impressions
1 Retweet
3 Likes
1 Bookmark
1 Reply
2 Quotes
Attackers target unpatched ShowDoc servers via CVE-2025-0520 https://t.co/6Kr6vgLc3j
@CwealthSentinel
15 Apr 2026
92 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 ShowDoc flaw under active exploitation CVE-2025-0520 is a critical RCE vulnerability caused by unrestricted file upload in ShowDoc < 2.8.7. Attackers can upload a malicious PHP file 🔗 https://t.co/WC8SWyQob5 #CyberSecurity #ShowDoc #CVE20250520 #Vulert
@vulert_official
15 Apr 2026
98 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️⚠️ CVE-2025-0520 (CVSS 9.4): Old ShowDoc file-upload bug is back in active exploitation and may lead to PHP web-shell RCE. 🔗FOFA Link: https://t.co/XSTI5LD11C 🎯7.6K+ Results are found on https://t.co/NBEEGu7ePJ in the past year. FOFA Query: app="ShowDoc" 🔖Refer
@fofabot
15 Apr 2026
1679 Impressions
14 Retweets
19 Likes
7 Bookmarks
0 Replies
0 Quotes
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/VGblFB4p3n via @TheHackersNews
@jackgoesvirtual
15 Apr 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#ShowDoc RCE #Flaw #CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/Wls7bTvut5
@ScyScan
15 Apr 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
攻撃者はCVE-2025-0520の脆弱性を悪用し、パッチが適用されていないShowDocサーバーを標的にしている Attackers target unpatched ShowDoc servers via CVE-2025-0520 #SecurityAffairs (Apr 14) https://t.co/OWNrSNabI0
@foxbook
14 Apr 2026
281 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ShowDocのRCE脆弱性CVE-2025-0520が、パッチ未適用サーバーで積極的に悪用されている ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers #HackerNews (Apr 14) https://t.co/cKAB4rFA8P
@foxbook
14 Apr 2026
223 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers target unpatched ShowDoc servers via CVE-2025-0520 - https://t.co/ardUK7GYat
@Whitehead4Jeff
14 Apr 2026
74 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#ShowDoc #RCE #Vulnerabilities #Flaw CVE-2025-0520 Actively #Exploited on #Unpatched_Servers https://t.co/H8HhOwr8IS https://t.co/0YjqxNqiUI
@omvapt
14 Apr 2026
90 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-0520 exploits unrestricted file uploads in ShowDoc, with a 9.4 CVSS score, are you patching your servers before it's too late? Source: ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers #ShowDocVulnerability #RCEFlaw #Cybersecurity https://t.co/S7W
@Soemailsecurity
14 Apr 2026
86 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/JD6O9R2FbT
@Tech_Newsletter
14 Apr 2026
77 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows attackers exploiting CVE-2025-0520 in unpatched ShowDoc servers to upload PHP web shells and establish persistent access. Post-compromise lateral movement through internal networks demonstrates the importance of runtime segmentation to limit blast radius.
@aviatrixtrc
14 Apr 2026
84 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ShowDoc #RCE #flaw #CVE-2025-0520 Actively #exploited on Un#patched Servers. Protect your machine against #exploits, update your software with #UCheck https://t.co/wfeUS4Am4f
@AdliceSoftware
14 Apr 2026
105 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【Attackers target unpatched ShowDoc servers via CVE-2025-0520】 ShowDocの重大RCE「CVE-2025-0520」が、未修正サーバーで実際に悪用されているとの報道。 認証不要のファイルアップロード不備により、外部公開された脆弱環境
@01ra66it
14 Apr 2026
268 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/3ROzmcWEQn via @TheHackersNews
@ABabino
14 Apr 2026
101 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
BREAKING: Critical RCE CVE-2025-0520 in ShowDoc (CVSS 9.4) is under active exploitation, with attackers hitting unpatched servers to run arbitrary code remotely. https://t.co/cCiAlcftjx
@threatcluster
14 Apr 2026
100 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers target unpatched ShowDoc servers via CVE-2025-0520 - https://t.co/Hhj2MZHmFD
@moton
14 Apr 2026
114 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical ShowDoc Vulnerability #CVE-2025-0520 Actively Exploited, Thousands of Servers at Risk + Video -Fact Checker: ✅: 2 ❌: 1 || 2/3 https://t.co/bDwRp2Bmsx
@UndercodeNews
14 Apr 2026
103 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
You updated your systems right? Because attackers are already inside the ones that didn’t. A critical flaw in ShowDoc (CVE-2025-0520) is now being actively exploited, putting unpatched servers at serious risk. #cybersecuritynews Full Story 👉 https://t.co/poJVQFPDwd https://t
@CSec88
14 Apr 2026
131 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers target unpatched ShowDoc servers via CVE-2025-0520 https://t.co/TH5d10baro
@hackplayers
14 Apr 2026
351 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apr 14, 2026 🚨 A critical RCE vulnerability (CVE-2025-0520) in ShowDoc is being actively exploited on unpatched servers. With a CVSS score of 9.4, immediate updates are essential to protect your data. https://t.co/TznO90CjZo
@kernyx64
14 Apr 2026
119 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[Security Affairs] Attackers target unpatched ShowDoc servers via CVE-2025-0520. A critical RCE flaw, tracked as CVE-2025-0520, in ShowDoc is being actively exploited, putting unpatched servers at serious risk. A critical remote code execution flaw,... https://t.co/We8uoLlrlj
@shah_sheikh
14 Apr 2026
122 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers target unpatched ShowDoc servers via CVE-2025-0520: A critical RCE flaw, tracked as CVE-2025-0520, in ShowDoc is being actively exploited, putting unpatched servers at serious risk. A critical remote code execution flaw, tracked as… https://t.co/paTdoIX8J4 https://t.c
@shah_sheikh
14 Apr 2026
120 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers target unpatched #ShowDoc servers via CVE-2025-0520 https://t.co/pz3jr1wv64 #securityaffairs #hacking
@securityaffairs
14 Apr 2026
207 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 ShowDoc RCE vulnerability actively exploited (CVE-2025-0520) Unrestricted file upload → web shell deployment + full server compromise Lesson: Old bugs don’t die — they wait. If you’re running unpatched apps, you’re already a target https://t.co/mwvuYJRwne
@VivekIntel
14 Apr 2026
166 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
iT4iNT SERVER ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/HxyYx3LJ7s VDS VPS Cloud #ShowDoc #CVE20250520 #CyberSecurity #InfoSec #Vulnerability
@it4int
14 Apr 2026
94 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
==== 👁️ ==== Security Alert 🔐 ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers A critical security... https://t.co/9nwZDQWB5L ID: 0e9a1cd652c8 #CyberAttack #InfoSec #DataBreach ================
@MonstersRunAll
14 Apr 2026
130 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/VENDNpoa7d
@Dinosn
14 Apr 2026
1194 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited https://t.co/Ha0oNjgzVH https://t.co/MjPi4BICtZ
@devsecopscv
14 Apr 2026
86 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical RCE flaw CVE-2025-0520 in ShowDoc allows attackers to upload malicious PHP files and execute code remotely. Affects versions before 2.8.7; fixed in Oct 2020 update. Exploited on unpatched servers. #ShowDoc #RemoteCode #China https://t.co/SFx29rVVM0
@TweetThreatNews
14 Apr 2026
180 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 #CVE-2025-0520: Unauthenticated Web Shell Uploads Exploited in the Wild – Patch Now! + Video https://t.co/oQ2JEriLbo Educational Purposes!
@UndercodeUpdate
14 Apr 2026
100 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 A ShowDoc flaw (CVSS 9.4) is now under active exploitation. CVE-2025-0520 lets attackers upload web shells via unauthenticated file upload → full server control. First attacks seen via a U.S. honeypot; ~2,000 instances remain exposed, mostly in China. https://t.co/mmYGbP9
@GlitchWolf_0609
14 Apr 2026
112 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers: A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The… https://t.co/otPUALWc0e https://
@shah_sheikh
14 Apr 2026
115 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://t.co/SIud78yEX7
@TheCyberSecHub
14 Apr 2026
625 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes