Memos
by Usememos
Source repositories
CVEs (78)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-29029 | Med | 0.33 | 6.1 | 0.01 | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the… | ||
| CVE-2024-29030 | Med | 0.31 | 5.8 | 0.01 | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file. | ||
| CVE-2024-29028 | Med | 0.31 | 5.8 | 0.01 | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1. | ||
| CVE-2022-4848 | Med | 0.30 | 5.7 | 0.01 | Dec 29, 2022 | Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2025-65798 | Med | 0.28 | 5.4 | 0.00 | Dec 8, 2025 | Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users. | ||
| CVE-2025-56760 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2025 | When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server. | ||
| CVE-2023-0109 | Med | 0.28 | 5.4 | 0.00 | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious… | ||
| CVE-2022-25978 | Med | 0.28 | 5.4 | 0.01 | Feb 15, 2023 | All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme. | ||
| CVE-2023-0112 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0111 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0110 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0108 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0107 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0106 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2022-4851 | Med | 0.28 | 5.3 | 0.01 | Dec 29, 2022 | Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4841 | Med | 0.28 | 5.4 | 0.01 | Dec 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4840 | Med | 0.28 | 5.4 | 0.01 | Dec 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4839 | Med | 0.28 | 5.4 | 0.01 | Dec 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4806 | Med | 0.28 | 5.3 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4802 | Med | 0.28 | 5.4 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. |
- risk 0.33cvss 6.1epss 0.01
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the…
- risk 0.31cvss 5.8epss 0.01
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.
- risk 0.31cvss 5.8epss 0.01
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.
- risk 0.30cvss 5.7epss 0.01
Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.28cvss 5.4epss 0.00
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
- risk 0.28cvss 4.3epss 0.00
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.
- risk 0.28cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious…
- risk 0.28cvss 5.4epss 0.01
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- risk 0.28cvss 5.3epss 0.01
Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.28cvss 5.3epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.28cvss 5.4epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
Page 3 of 4