VYPR

Showdoc

by Star7th

Source repositories

CVEs (4)

  • CVE-2025-0520CriApr 29, 2025
    risk 0.54cvss —epss 0.03

    An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.

  • CVE-2026-6982MedApr 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Controller/PageController.class.PHP of the component API Page Sort Endpoint. Executing a manipulation of the…

  • CVE-2018-19433MedNov 22, 2018
    risk 0.40cvss 6.1epss 0.01

    ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.

  • CVE-2026-86644LowSep 8, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross site scripting. The attack may be launched…