VYPR

Memos

by Usememos

Source repositories

CVEs (78)

  • CVE-2022-4811HigDec 28, 2022
    risk 0.47cvss 8.3epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

  • CVE-2024-41659HigAug 20, 2024
    risk 0.46cvss 8.1epss 0.01

    memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request,…

  • CVE-2022-4796HigDec 28, 2022
    risk 0.46cvss 8.1epss 0.01

    Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4734HigDec 27, 2022
    risk 0.46cvss 8.1epss 0.01

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4687HigDec 23, 2022
    risk 0.46cvss 8.1epss 0.01

    Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2025-65795HigDec 8, 2025
    risk 0.42cvss 7.5epss 0.00

    Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

  • CVE-2023-4698HigSep 1, 2023
    risk 0.42cvss 7.5epss 0.01

    Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

  • CVE-2022-4767HigDec 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Denial of Service in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2025-65797MedDec 8, 2025
    risk 0.35cvss 6.5epss 0.00

    Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).

  • CVE-2025-56761MedSep 3, 2025
    risk 0.35cvss 5.4epss 0.00

    Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their…

  • CVE-2022-4863MedDec 30, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4850MedDec 29, 2022
    risk 0.35cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4849MedDec 29, 2022
    risk 0.35cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4847MedDec 29, 2022
    risk 0.35cvss 6.5epss 0.01

    Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4846MedDec 29, 2022
    risk 0.35cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4812MedDec 28, 2022
    risk 0.35cvss 6.5epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4800MedDec 28, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4799MedDec 28, 2022
    risk 0.35cvss 6.5epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4683MedDec 23, 2022
    risk 0.35cvss 6.5epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.

  • CVE-2026-30586MedJun 2, 2026
    risk 0.33cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages