showdoc CVE Vulnerabilities & Metrics

Focus on showdoc vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About showdoc Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with showdoc. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total showdoc CVEs: 41
Earliest CVE date: 02 Sep 2018, 18:29 UTC
Latest CVE date: 22 Mar 2022, 08:15 UTC

Latest CVE reference: CVE-2022-1034

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical showdoc CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.54

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 19
4.0-6.9 19
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS showdoc CVEs

These are the five CVEs with the highest CVSS scores for showdoc, sorted by severity first and recency.

All CVEs for showdoc

CVE-2022-1034 showdoc vulnerability CVSS: 6.5 22 Mar 2022, 08:15 UTC

There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0967 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 16:15 UTC

Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0966 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 16:15 UTC

Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10.

CVE-2022-0965 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 16:15 UTC

Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0964 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 16:15 UTC

Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0942 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 14:15 UTC

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0957 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 13:15 UTC

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0956 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 13:15 UTC

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.

CVE-2022-0951 showdoc vulnerability CVSS: 4.3 15 Mar 2022, 09:15 UTC

File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0950 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 09:15 UTC

Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0945 showdoc vulnerability CVSS: 3.5 15 Mar 2022, 04:15 UTC

Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-0962 showdoc vulnerability CVSS: 3.5 14 Mar 2022, 16:15 UTC

Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0960 showdoc vulnerability CVSS: 3.5 14 Mar 2022, 15:15 UTC

Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0946 showdoc vulnerability CVSS: 3.5 14 Mar 2022, 14:15 UTC

Stored XSS viva cshtm file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-0941 showdoc vulnerability CVSS: 3.5 14 Mar 2022, 13:15 UTC

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-0940 showdoc vulnerability CVSS: 3.5 14 Mar 2022, 11:15 UTC

Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-0938 showdoc vulnerability CVSS: 3.5 14 Mar 2022, 08:15 UTC

Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.

CVE-2022-0937 showdoc vulnerability CVSS: 3.5 14 Mar 2022, 03:15 UTC

Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0880 showdoc vulnerability CVSS: 3.5 12 Mar 2022, 04:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

CVE-2022-0409 showdoc vulnerability CVSS: 6.8 19 Feb 2022, 05:15 UTC

Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.

CVE-2022-0362 showdoc vulnerability CVSS: 7.5 26 Jan 2022, 13:15 UTC

SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.

CVE-2021-4172 showdoc vulnerability CVSS: 3.5 22 Jan 2022, 12:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

CVE-2022-0079 showdoc vulnerability CVSS: 5.0 03 Jan 2022, 03:15 UTC

showdoc is vulnerable to Generation of Error Message Containing Sensitive Information

CVE-2021-4168 showdoc vulnerability CVSS: 6.8 26 Dec 2021, 14:15 UTC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-4000 showdoc vulnerability CVSS: 5.8 03 Dec 2021, 11:15 UTC

showdoc is vulnerable to URL Redirection to Untrusted Site

CVE-2021-4017 showdoc vulnerability CVSS: 6.8 01 Dec 2021, 11:15 UTC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-3993 showdoc vulnerability CVSS: 4.3 01 Dec 2021, 11:15 UTC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-3990 showdoc vulnerability CVSS: 4.3 01 Dec 2021, 11:15 UTC

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

CVE-2021-3989 showdoc vulnerability CVSS: 5.8 01 Dec 2021, 11:15 UTC

showdoc is vulnerable to URL Redirection to Untrusted Site

CVE-2021-3776 showdoc vulnerability CVSS: 5.8 13 Nov 2021, 10:15 UTC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-3775 showdoc vulnerability CVSS: 5.8 13 Nov 2021, 10:15 UTC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-3683 showdoc vulnerability CVSS: 4.3 13 Nov 2021, 10:15 UTC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-41745 showdoc vulnerability CVSS: 7.5 22 Oct 2021, 12:15 UTC

ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

CVE-2021-36440 showdoc vulnerability CVSS: 7.5 08 Sep 2021, 21:15 UTC

Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'.

CVE-2021-3678 showdoc vulnerability CVSS: 4.3 04 Aug 2021, 14:15 UTC

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

CVE-2021-3680 showdoc vulnerability CVSS: 4.0 04 Aug 2021, 13:15 UTC

showdoc is vulnerable to Missing Cryptographic Step

CVE-2018-19621 showdoc vulnerability CVSS: 4.3 28 Nov 2018, 08:29 UTC

server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.

CVE-2018-19620 showdoc vulnerability CVSS: 4.0 28 Nov 2018, 08:29 UTC

ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.

CVE-2018-19609 showdoc vulnerability CVSS: 4.0 27 Nov 2018, 16:29 UTC

ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.

CVE-2018-19433 showdoc vulnerability CVSS: 4.3 22 Nov 2018, 05:29 UTC

ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.

CVE-2018-16342 showdoc vulnerability CVSS: 3.5 02 Sep 2018, 18:29 UTC

ShowDoc v1.8.0 has XSS via a new page.