Memos
by Usememos
Source repositories
CVEs (78)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-51584 | Cri | 0.57 | 9.8 | 0.00 | Aug 11, 2026 | An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's… | ||
| CVE-2025-50738 | Cri | 0.57 | 9.8 | 0.02 | Jul 29, 2025 | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the… | ||
| CVE-2025-22952 | Cri | 0.57 | 9.8 | 0.03 | Feb 27, 2025 | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. | ||
| CVE-2023-4696 | Cri | 0.57 | 9.8 | 0.01 | Sep 1, 2023 | Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2022-4686 | Cri | 0.57 | 9.8 | 0.01 | Dec 23, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2026-71272 | Hig | 0.55 | 8.5 | 0.00 | Aug 5, 2026 | Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather… | ||
| CVE-2026-71271 | Hig | 0.55 | 8.5 | 0.00 | Aug 5, 2026 | Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in… | ||
| CVE-2022-4866 | Cri | 0.52 | 9.0 | 0.01 | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4865 | Cri | 0.52 | 9.0 | 0.01 | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2023-5036 | Hig | 0.50 | 8.8 | 0.00 | Sep 18, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1. | ||
| CVE-2023-4697 | Hig | 0.50 | 8.8 | 0.01 | Sep 1, 2023 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2022-4844 | Hig | 0.50 | 8.8 | 0.00 | Dec 29, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4809 | Hig | 0.50 | 8.8 | 0.01 | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4808 | Hig | 0.50 | 8.8 | 0.00 | Dec 28, 2022 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4803 | Hig | 0.50 | 8.8 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4689 | Hig | 0.50 | 8.8 | 0.01 | Dec 23, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2022-4688 | Hig | 0.50 | 8.8 | 0.01 | Dec 23, 2022 | Improper Authorization in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2022-4684 | Hig | 0.50 | 8.8 | 0.01 | Dec 23, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2024-21635 | Hig | 0.49 | 7.5 | 0.00 | Nov 14, 2025 | Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds that their account has been compromised,… | ||
| CVE-2026-51583 | Hig | 0.48 | 8.5 | 0.00 | Aug 11, 2026 | An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address. |
- risk 0.57cvss 9.8epss 0.00
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's…
- risk 0.57cvss 9.8epss 0.02
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the…
- risk 0.57cvss 9.8epss 0.03
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.57cvss 9.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.55cvss 8.5epss 0.00
Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather…
- risk 0.55cvss 8.5epss 0.00
Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in…
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
- risk 0.50cvss 8.8epss 0.01
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.50cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.00
Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.50cvss 8.8epss 0.01
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.49cvss 7.5epss 0.00
Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds that their account has been compromised,…
- risk 0.48cvss 8.5epss 0.00
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.
Page 1 of 4