VYPR

Memos

by Usememos

Source repositories

CVEs (78)

  • CVE-2026-51584CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's…

  • CVE-2025-50738CriJul 29, 2025
    risk 0.57cvss 9.8epss 0.02

    The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the…

  • CVE-2025-22952CriFeb 27, 2025
    risk 0.57cvss 9.8epss 0.03

    elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.

  • CVE-2023-4696CriSep 1, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

  • CVE-2022-4686CriDec 23, 2022
    risk 0.57cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2026-71272HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather…

  • CVE-2026-71271HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in…

  • CVE-2022-4866CriDec 31, 2022
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4865CriDec 31, 2022
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2023-5036HigSep 18, 2023
    risk 0.50cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

  • CVE-2023-4697HigSep 1, 2023
    risk 0.50cvss 8.8epss 0.01

    Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

  • CVE-2022-4844HigDec 29, 2022
    risk 0.50cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4809HigDec 28, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4808HigDec 28, 2022
    risk 0.50cvss 8.8epss 0.00

    Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4803HigDec 28, 2022
    risk 0.50cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4689HigDec 23, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2022-4688HigDec 23, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2022-4684HigDec 23, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2024-21635HigNov 14, 2025
    risk 0.49cvss 7.5epss 0.00

    Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds that their account has been compromised,…

  • CVE-2026-51583HigAug 11, 2026
    risk 0.48cvss 8.5epss 0.00

    An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.

Page 1 of 4