Skip to main content

Vendor/product archive

usememos / memos CVEs

Beta · best-effort

73 CVEs tagged to usememos / memos6 Critical, 18 High, 49 Medium, 0 Low, 0 Unrated.

CVE-2025-65799

Published Dec 8, 2025

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65797

Published Dec 8, 2025

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65795

Published Dec 8, 2025

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65798

Published Dec 8, 2025

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65796

Published Dec 8, 2025

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21635

Published Nov 14, 2025

Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Acce…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-56761

Published Sep 3, 2025

Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uplo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-56760

Published Sep 3, 2025

When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing ar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50738

Published Jul 29, 2025

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser aut…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-22952

Published Feb 27, 2025

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
30.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-0109

Published Nov 15, 2024

A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a ma…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41659

Published Aug 20, 2024

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Al…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29029

Published Apr 19, 2024

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the int…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29030

Published Apr 19, 2024

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the inte…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29028

Published Apr 19, 2024

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5036

Published Sep 18, 2023

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4698

Published Sep 1, 2023

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4697

Published Sep 1, 2023

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4696

Published Sep 1, 2023

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-25978

Published Feb 15, 2023

All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0112

Published Jan 7, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0111

Published Jan 7, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0110

Published Jan 7, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0108

Published Jan 7, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0107

Published Jan 7, 2023

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 73 CVEsPage 1 of 3