GHSA-mw75-qvfr-hpmr
GitHub Security Advisory
Cross-site Scripting in ShowDoc
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
ShowDoc is vulnerable to stored cross-site scripting through file upload in versions 2.10.3 and prior. A patch is available and anticipated to be part of version 2.10.4.
Affected Packages
Packagist
showdoc/showdoc
Affected versions:
0
(fixed in 2.10.4)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 13, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.