ShowDoc Servers Become Easy RCE Targets

Unpatched ShowDoc installs are turning into low-cost remote code execution targets. The standard response is to treat this as a routine web app bug, but the real issue is that unrestricted file upload lets an attacker plant a PHP web shell and take over the server. CVE-2025-0520 affects ShowDoc versions before 2.8.7 and is fixed in 2.8.7. VulnCheck says the flaw is now being actively exploited, and there are more than 2,000 internet-exposed ShowDoc instances online, most of them in China. That makes exposed older deployments a mass-target pool for opportunistic attacks. Patching removes the flaw, but any server that was reachable before the fix may already need a separate review for dropped web shells and other changes.

Part of the PlainSec briefing for 2026-04-15

Sources