Memos
by Usememos
Source repositories
CVEs (78)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-4811 | Hig | 0.47 | 8.3 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1. | ||
| CVE-2024-41659 | Hig | 0.46 | 8.1 | 0.01 | Aug 20, 2024 | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request,… | ||
| CVE-2022-4796 | Hig | 0.46 | 8.1 | 0.01 | Dec 28, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4734 | Hig | 0.46 | 8.1 | 0.01 | Dec 27, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4687 | Hig | 0.46 | 8.1 | 0.01 | Dec 23, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2025-65795 | Hig | 0.42 | 7.5 | 0.00 | Dec 8, 2025 | Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request. | ||
| CVE-2023-4698 | Hig | 0.42 | 7.5 | 0.01 | Sep 1, 2023 | Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2022-4767 | Hig | 0.42 | 7.5 | 0.01 | Dec 27, 2022 | Denial of Service in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2025-65797 | Med | 0.35 | 6.5 | 0.00 | Dec 8, 2025 | Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS). | ||
| CVE-2025-56761 | Med | 0.35 | 5.4 | 0.00 | Sep 3, 2025 | Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their… | ||
| CVE-2022-4863 | Med | 0.35 | 6.5 | 0.01 | Dec 30, 2022 | Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4850 | Med | 0.35 | 6.5 | 0.00 | Dec 29, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4849 | Med | 0.35 | 6.5 | 0.00 | Dec 29, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4847 | Med | 0.35 | 6.5 | 0.01 | Dec 29, 2022 | Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4846 | Med | 0.35 | 6.5 | 0.00 | Dec 29, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4812 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4800 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2022 | Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4799 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4683 | Med | 0.35 | 6.5 | 0.00 | Dec 23, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2026-30586 | Med | 0.33 | 6.1 | 0.00 | Jun 2, 2026 | Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages |
- risk 0.47cvss 8.3epss 0.01
Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.
- risk 0.46cvss 8.1epss 0.01
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request,…
- risk 0.46cvss 8.1epss 0.01
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.46cvss 8.1epss 0.01
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.46cvss 8.1epss 0.01
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.42cvss 7.5epss 0.00
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
- risk 0.42cvss 7.5epss 0.01
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.42cvss 7.5epss 0.01
Denial of Service in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).
- risk 0.35cvss 5.4epss 0.00
Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their…
- risk 0.35cvss 6.5epss 0.01
Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.01
Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.01
Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.33cvss 6.1epss 0.00
Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages
Page 2 of 4