VYPR

Memos

by Usememos

Source repositories

CVEs (78)

  • CVE-2024-29029MedApr 19, 2024
    risk 0.33cvss 6.1epss 0.01

    memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the…

  • CVE-2024-29030MedApr 19, 2024
    risk 0.31cvss 5.8epss 0.01

    memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.

  • CVE-2024-29028MedApr 19, 2024
    risk 0.31cvss 5.8epss 0.01

    memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.

  • CVE-2022-4848MedDec 29, 2022
    risk 0.30cvss 5.7epss 0.01

    Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2025-65798MedDec 8, 2025
    risk 0.28cvss 5.4epss 0.00

    Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

  • CVE-2025-56760MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.

  • CVE-2023-0109MedNov 15, 2024
    risk 0.28cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious…

  • CVE-2022-25978MedFeb 15, 2023
    risk 0.28cvss 5.4epss 0.01

    All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.

  • CVE-2023-0112MedJan 7, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

  • CVE-2023-0111MedJan 7, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

  • CVE-2023-0110MedJan 7, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

  • CVE-2023-0108MedJan 7, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

  • CVE-2023-0107MedJan 7, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

  • CVE-2023-0106MedJan 7, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

  • CVE-2022-4851MedDec 29, 2022
    risk 0.28cvss 5.3epss 0.01

    Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4841MedDec 29, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4840MedDec 29, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4839MedDec 29, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4806MedDec 28, 2022
    risk 0.28cvss 5.3epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4802MedDec 28, 2022
    risk 0.28cvss 5.4epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.