CVE-2025-0520Active Exploitation

HIGHCVSS 9.4 · CRITICAL

Exploitation observed; activity peaked at 37 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

6.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 57 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 60 mentions across 10 observed days

What's happening

  • Active exploitation reported across 57 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 41 signals
  • General: 1 classified signal
  • Peaked 8d ago at 37 mentions (2026-04-14); latest day: 1
  • 60 total mentions across 10 days

Deep dive

Activity timeline60 mentions / 10d
09192837Mentions · 2026-04-11: 1Mentions · 2026-04-14: 37Mentions · 2026-04-15: 9Mentions · 2026-04-16: 1Mentions · 2026-04-17: 4Mentions · 2026-04-18: 4Mentions · 2026-04-19: 1Mentions · 2026-04-27: 1Mentions · 2026-05-30: 1Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-04-15: 2PoC Mentioned / Linked · 2026-04-19: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-14: 37Active Exploitation · 2026-04-15: 9Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-17: 4Active Exploitation · 2026-04-18: 4Active Exploitation · 2026-04-19: 1Patch / Workaround · 2026-04-14: 7Patch / Workaround · 2026-04-15: 2Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-18: 2Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-14: 23Technical Details · 2026-04-15: 6Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-18: 4Technical Details · 2026-04-19: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-30: 1Technical Details · 2026-08-17: 104-1104-1404-1504-1604-1704-1804-1904-2705-3008-17
Signal classification4 categories
Active Exploitation
5795.0%
Patch
11.7%
General
11.7%
Disclosure
11.7%
Referenced assets33 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-111
Active Exploitation1
2026-04-1437
Active Exploitation37
2026-04-159
Active Exploitation9
2026-04-161
Active Exploitation1
2026-04-174
Active Exploitation4
2026-04-184
Active Exploitation4
2026-04-191
Active Exploitation1
2026-04-271
Patch1
2026-05-301
General1
2026-08-171
Disclosure1
Full discourse20 posts
  • Caitlin Condon@catc0n
    Active Exploitation

    🐚New VulnCheck KEV: Our Canaries detected first-time exploitation of CVE-2025-0520, an unauth file upload bug in open-source Chinese doc management software ShowDoc. The VulnCheck-observed exploit drops a webshell. 📈 There are 2K+ instances online, primarily in China. https://t.co/vqiJaVRLi3

    Post summary

    Active exploitation of CVE-2025-0520 is being seen with a webshell drop across over 2000 instances, mainly in China.

    312054245.8K
    3.6K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 A ShowDoc flaw (CVSS 9.4) is now under active exploitation. CVE-2025-0520 lets attackers upload web shells via unauthenticated file upload → full server control. First attacks seen via a U.S. honeypot; ~2,000 instances remain exposed, mostly in China. 🔗 Details → https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html

    Post summary

    The tweet reports that CVE‑2025‑0520 in ShowDoc is being actively exploited: attackers upload web shells via unauthenticated file upload, with about 2,000 instances exposed, and links to further details.

    417253810.6K
    1.7M followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2025-0520 (CVSS 9.4): Old ShowDoc file-upload bug is back in active exploitation and may lead to PHP web-shell RCE. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJTaG93RG9jIg== 🎯7.6K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="ShowDoc" 🔖Refer: https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE-2025-0520, a high‑severity ShowDoc file‑upload vulnerability, is reported to be actively exploited, enabling PHP web‑shell remote code execution.

    018028113.2K
    14.3K followersView on X
  • Hackread.com@HackRead
    Active Exploitation

    📢⚠️ Hackers are exploiting a 5-year-old #ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. Read: https://hackread.com/showdoc-vulnerability-patch-2020-server-takeover/ #CyberSecurity #Vulnerability #CyberAttacks

    Post summary

    The post reports active exploitation of CVE‑2025‑0520, describing RCE via web shells and worldwide server takeovers, but offers no link to PoC, exploit code, or patch.

    0602062.0K
    114.2K followersView on X
  • Cytex@cytexsmb
    Active Exploitation

    🚨 ShowDoc Critical Flaw Under Active Attack! A critical unrestricted file upload vulnerability in ShowDoc is being actively exploited in the wild, despite a patch being available since October 2020. 🔴 CVE-2025-0520 CVSS 9.4 The flaw allows unauthenticated attackers to upload arbitrary PHP files and execute code on vulnerable servers. Researchers have observed exploitation attempts against a U.S.-based honeypot, marking the first documented active use of this six-year-old vulnerability. The Vulnerability → Unrestricted file upload due to improper validation of file extensions. → Unauthenticated attacker can upload a web shell and achieve remote code execution. → Affects ShowDoc versions before 2.8.7. 🩹 Patch History → Vulnerability addressed in ShowDoc version 2.8.7, released October 2020. → Current ShowDoc version is 3.8.1. → The patch has been available for over six years. 🎯 Active Exploitation → First documented active exploitation observed recently. → Attackers dropped a web shell on a U.S.-based honeypot running a vulnerable version. → Over 2,000 ShowDoc instances are publicly accessible online. → Majority of exposed instances are located in China. Threat actors are increasingly exploiting N-day vulnerabilities, flaws with patches available for years, targeting organizations that fail to update. The exploit window for this vulnerability closed in 2020, yet thousands of servers remain exposed. 🛡️ Mitigation → Update ShowDoc to the latest version (3.8.1) immediately. → Versions 2.8.7 and later contain the fix. → No workaround addresses the flaw fully, patching is required.

    Post summary

    The post warns that a long‑patched file‑upload flaw (CVE‑2025‑0520) in ShowDoc is actively exploited in the wild, with over 2,000 exposed instances, and urges immediate upgrade to v3.8.1.

    11231292
    850 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-0520 - critical 🚨 ShowDoc - Remote Code Execution > The open-source API documentation tool ShowDoc had a remote code execution vulnerabil... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-0520 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the new CVE‑2025‑0520 for ShowDoc, describing it as a remote code execution vulnerability, but provides no PoC, exploit, or mitigation details.

    00052456
    1.3K followersView on X
  • Tathagata M.@tatha_gautama
    Active Exploitation

    • #CyberSecurity #CyberCrime #DataHack #DataPrivacy #DataTheft #DataLeaks #DataBreach 💾 • • #Hacked #Malware #Spyware #Zerodays #Ransomware #Phishing #Backdoor #RCE #RAT ☠️ • » ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html

    Post summary

    The tweet reports that ShowDoc RCE flaw CVE‑2025‑0520 is actively exploited on unpatched servers, without providing a PoC or patch information.

    40000557
    401 followersView on X
  • VulnCheck@VulnCheckAI
    Active Exploitation

    CVE-2025-0520 (ShowDoc file upload bug) is now being exploited. VulnCheck’s Canary Intelligence spotted first activity, with Caitlin Condon sharing early details and @TheHackersNews covering it. Full story: https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html

    Post summary

    The text reports that CVE‑2025‑0520, a ShowDoc file upload flaw, is currently being exploited in the wild, without providing PoC, exploit code, patches, or detailed vulnerability data.

    01020677
    714 followersView on X
  • CyberSecurity88@CSec88
    Active Exploitation

    You updated your systems right? Because attackers are already inside the ones that didn’t. A critical flaw in ShowDoc (CVE-2025-0520) is now being actively exploited, putting unpatched servers at serious risk. #cybersecuritynews Full Story 👉 https://cybersecurity88.com/news/showdoc-rce-vulnerability-cve-2025-0520-actively-exploited-to-compromise-unpatched-servers/ https://t.co/kHNy0tRxzZ

    Post summary

    The tweet announces that CVE‑2025‑0520 in ShowDoc is actively being exploited in the wild, putting unpatched servers at serious risk.

    00030204
    542 followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Active Exploitation

    Attackers target unpatched #ShowDoc servers via CVE-2025-0520 https://securityaffairs.com/190790/uncategorized/attackers-target-unpatched-showdoc-servers-via-cve-2025-0520.html #securityaffairs #hacking

    Post summary

    The tweet alerts that attackers are actively exploiting ShowDoc servers vulnerabilities identified by CVE-2025-0520 against unpatched installations.

    01020608
    37.6K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet reports that ShowDoc's CVE-2025-0520 RCE flaw is actively exploited on unpatched servers, providing no PoC, exploit code, patch, or technical details.

    00020703
    194.4K followersView on X
  • SoEmailSecurity@Soemailsecurity
    Active Exploitation

    CVE-2025-0520 exploits unrestricted file uploads in ShowDoc, with a 9.4 CVSS score, are you patching your servers before it's too late? Source: ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers #ShowDocVulnerability #RCEFlaw #Cybersecurity https://t.co/S7Wi8osbGx

    Post summary

    The tweet emphasizes that CVE-2025-0520, an unrestricted file upload flaw in ShowDoc with a 9.4 CVSS score, is actively exploited on unpatched servers and urges immediate patching.

    00010129
    56 followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html

    Post summary

    The post reports that CVE-2025-0520, a Remote Code Execution flaw in ShowDoc, is being actively exploited on unpatched servers, but no PoC or exploit code details are provided in this excerpt.

    000101.3K
    157.5K followersView on X
  • Popsy🎗❤️🦍@GlitchWolf_0609
    Active Exploitation

    🚨 A ShowDoc flaw (CVSS 9.4) is now under active exploitation. CVE-2025-0520 lets attackers upload web shells via unauthenticated file upload → full server control. First attacks seen via a U.S. honeypot; ~2,000 instances remain exposed, mostly in China. https://t.co/mmYGbP9VTs

    Post summary

    The tweet reports that CVE-2025-0520 is actively being exploited, allowing attackers to upload web shells and achieve full server control, with thousands of exposed instances worldwide.

    00010161
    211 followersView on X
  • zerizeri(インフラエンジニア技術ブログ)@zerizerizeri_bl
    General

    【WAFログ速報】 128.199.129.101(1回): 2026-05-30 11:33:56に/index.php?s=/home/page/uploadImgに対し不正なファイル名を含むファイルアップロードを検知。(CVE-2025-0520) https://cvereports.com/reports/CVE-2025-0520 #WAF #セキュリティ #脅威検知 https://t.co/7sRTt6qzMk

    Post summary

    A WAF alert reports a file‑upload anomaly tied to CVE‑2025‑0520, with a reference to a CVE report but no PoC, exploit code, patch, or false‑positive claim.

    0000047
    45 followersView on X
  • TheCybersecurity.club@TheCyberse46292
    Patch

    Stop scrolling if you use ShowDoc ⚠️ A critical flaw (CVE-2025-0520, 9.4/10) lets hackers upload malicious files with no checks—risking server takeover, data theft, and ransomware. Avoid unverified files & update ASAP. #CyberSecurity #DataBreach #InfoSec

    Post summary

    A newly disclosed CVE-2025-0520 allows attackers to upload malicious files without validation, potentially leading to server takeover and ransomware. Users are warned to avoid unverified files and apply updates immediately.

    00000586
    3 followersView on X
  • TechNowPulse@TechNowPulse
    Active Exploitation

    Hackers are exploiting a 5-year-old ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. https://hackread.com/showdoc-vulnerability-patch-2020-server-takeover/

    Post summary

    The post reports that CVE-2025-0520, a five-year-old ShowDoc flaw, is being actively exploited worldwide with web shells enabling remote code execution and full server takeover, and a patch is available.

    00000423
    21 followersView on X
  • TechNowPulse@TechNowPulse
    Active Exploitation

    Hackers are exploiting a 5-year-old ShowDoc vulnerability (CVE-2025-0520) to deploy web shells, enabling RCE and full server takeover worldwide. https://hackread.com/showdoc-vulnerability-patch-2020-server-takeover/

    Post summary

    The article reports that ShowDoc CVE‑2025‑0520 is being actively exploited worldwide by deploying web shells that enable remote code execution and full server takeover, but it does not provide a PoC, patch, or exploit code details.

    00000487
    21 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 ShowDoc vulnerability patched in 2020 now exploited for server takeovers Unauth file upload (CVE-2025-0520) → web shell + RCE + attacker foothold 💡 Lesson: Unpatched edge services become long-term entry points ⚠️ Action: Patch immediately, hunt web shells, reduce internet exposure https://hackread.com/showdoc-vulnerability-patch-2020-server-takeovers/

    Post summary

    ShowDoc’s previously patched CVE‑2025‑0520 file‑upload flaw is currently being actively exploited for server takeovers; urgent patching and web‑shell hunting are advised.

    00000673
    7.6K followersView on X
  • PurpleOps@PurpleOps_io
    Active Exploitation

    🔍 𝐒𝐡𝐨𝐰𝐃𝐨𝐜 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐲 𝐏𝐚𝐭𝐜𝐡𝐞𝐝 𝐢𝐧 𝟐𝟎𝟐𝟎 𝐍𝐨𝐰 𝐔𝐬𝐞𝐝 𝐢𝐧 𝐀𝐜𝐭𝐢𝐯𝐞 𝐒𝐞𝐫𝐯𝐞𝐫 𝐓𝐚𝐤𝐞𝐨𝐯𝐞𝐫𝐬 • Hackers are exploiting a 5-year-old ShowDoc vulnerability (CVE-2025-0520) for server takeovers. • The flaw is an unrestricted file upload (CVSS 9.4), enabling web shell deployment and remote code execution. • Many ShowDoc instances, particularly in China, remain unpatched since a fix was released in October 2020. • Recent attacks involve deploying web shells to gain full control of vulnerable systems worldwide. An old ShowDoc vulnerability, fixed in 2020, is now actively exploited to achieve remote code execution and full server control on unpatched systems.

    Post summary

    ShowDoc CVE-2025-0520, an unrestricted file upload flaw, is actively exploited worldwide to deploy web shells and achieve remote code execution on systems that remain unpatched since 2020.

    00000458
    99 followersView on X

Explore more