Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Showdoc

41 known vulnerabilities

3
CRITICAL
4
HIGH
34
MEDIUM

Top Products

showdoc 41
41 CVEs
7.2
CVE-2022-1034

There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.

5.4
CVE-2022-0967

Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0966

Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10.

5.4
CVE-2022-0965

Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0964

Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0942

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0957

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0956

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.

6.1
CVE-2022-0951

File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0950

Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0945

Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.

5.4
CVE-2022-0962

Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0960

Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0946

Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.

5.4
CVE-2022-0941

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.

5.4
CVE-2022-0940

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.

5.4
CVE-2022-0938

Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.

5.4
CVE-2022-0937

Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.

5.4
CVE-2022-0880

Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

7.8
CVE-2022-0409

Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.

9.8
CVE-2022-0362

SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.

5.4
CVE-2021-4172

Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

5.3
CVE-2022-0079

showdoc is vulnerable to Generation of Error Message Containing Sensitive Information

8.8
CVE-2021-4168

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

6.1
CVE-2021-4000

showdoc is vulnerable to URL Redirection to Untrusted Site

8.8
CVE-2021-4017

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

6.5
CVE-2021-3993

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

6.5
CVE-2021-3990

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

6.1
CVE-2021-3989

showdoc is vulnerable to URL Redirection to Untrusted Site

5.4
CVE-2021-3776

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

5.4
CVE-2021-3775

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

6.5
CVE-2021-3683

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

9.8
CVE-2021-41745

ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

9.8
CVE-2021-36440

Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' paramete

5.9
CVE-2021-3678

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

4.9
CVE-2021-3680

showdoc is vulnerable to Missing Cryptographic Step

6.5
CVE-2018-19621

server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.

4.3
CVE-2018-19620

ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.

6.5
CVE-2018-19609

ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstr

6.1
CVE-2018-19433

ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.

5.4
CVE-2018-16342

ShowDoc v1.8.0 has XSS via a new page.

Frequently Asked Questions

How many CVEs affect Showdoc?

Showdoc has 41 CVE records in our database, including 3 critical and 4 high severity vulnerabilities.

What are the most severe Showdoc vulnerabilities?

Showdoc has 3 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Showdoc vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Showdoc products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Showdoc Vulnerabilities

CyberStrike scans your infrastructure for Showdoc vulnerabilities and provides real-time remediation guidance.

Get Started