Vendor CVEs
Usememos
All CVEs
78 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-51584 | Cri | 0.57 | 9.8 | 0.00 | Aug 11, 2026 | An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's… | ||
| CVE-2025-50738 | Cri | 0.57 | 9.8 | 0.02 | Jul 29, 2025 | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the… | ||
| CVE-2025-22952 | Cri | 0.57 | 9.8 | 0.03 | Feb 27, 2025 | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. | ||
| CVE-2023-4696 | Cri | 0.57 | 9.8 | 0.01 | Sep 1, 2023 | Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2022-4686 | Cri | 0.57 | 9.8 | 0.01 | Dec 23, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2026-71272 | Hig | 0.55 | 8.5 | 0.00 | Aug 5, 2026 | Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather… | ||
| CVE-2026-71271 | Hig | 0.55 | 8.5 | 0.00 | Aug 5, 2026 | Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in… | ||
| CVE-2022-4866 | Cri | 0.52 | 9.0 | 0.01 | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4865 | Cri | 0.52 | 9.0 | 0.01 | Dec 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2023-5036 | Hig | 0.50 | 8.8 | 0.00 | Sep 18, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1. | ||
| CVE-2023-4697 | Hig | 0.50 | 8.8 | 0.01 | Sep 1, 2023 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2022-4844 | Hig | 0.50 | 8.8 | 0.00 | Dec 29, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4809 | Hig | 0.50 | 8.8 | 0.01 | Dec 28, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4808 | Hig | 0.50 | 8.8 | 0.00 | Dec 28, 2022 | Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4803 | Hig | 0.50 | 8.8 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4689 | Hig | 0.50 | 8.8 | 0.01 | Dec 23, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2022-4688 | Hig | 0.50 | 8.8 | 0.01 | Dec 23, 2022 | Improper Authorization in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2022-4684 | Hig | 0.50 | 8.8 | 0.01 | Dec 23, 2022 | Improper Access Control in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2024-21635 | Hig | 0.49 | 7.5 | 0.00 | Nov 14, 2025 | Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds that their account has been compromised,… | ||
| CVE-2026-51583 | Hig | 0.48 | 8.5 | 0.00 | Aug 11, 2026 | An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address. | ||
| CVE-2022-4811 | Hig | 0.47 | 8.3 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1. | ||
| CVE-2024-41659 | Hig | 0.46 | 8.1 | 0.01 | Aug 20, 2024 | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request,… | ||
| CVE-2022-4796 | Hig | 0.46 | 8.1 | 0.01 | Dec 28, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4734 | Hig | 0.46 | 8.1 | 0.01 | Dec 27, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4687 | Hig | 0.46 | 8.1 | 0.01 | Dec 23, 2022 | Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2025-65795 | Hig | 0.42 | 7.5 | 0.00 | Dec 8, 2025 | Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request. | ||
| CVE-2023-4698 | Hig | 0.42 | 7.5 | 0.01 | Sep 1, 2023 | Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2. | ||
| CVE-2022-4767 | Hig | 0.42 | 7.5 | 0.01 | Dec 27, 2022 | Denial of Service in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2025-65797 | Med | 0.35 | 6.5 | 0.00 | Dec 8, 2025 | Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS). | ||
| CVE-2025-56761 | Med | 0.35 | 5.4 | 0.00 | Sep 3, 2025 | Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their… | ||
| CVE-2022-4863 | Med | 0.35 | 6.5 | 0.01 | Dec 30, 2022 | Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4850 | Med | 0.35 | 6.5 | 0.00 | Dec 29, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4849 | Med | 0.35 | 6.5 | 0.00 | Dec 29, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4847 | Med | 0.35 | 6.5 | 0.01 | Dec 29, 2022 | Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4846 | Med | 0.35 | 6.5 | 0.00 | Dec 29, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4812 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4800 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2022 | Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4799 | Med | 0.35 | 6.5 | 0.01 | Dec 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2022-4683 | Med | 0.35 | 6.5 | 0.00 | Dec 23, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0. | ||
| CVE-2026-30586 | Med | 0.33 | 6.1 | 0.00 | Jun 2, 2026 | Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages | ||
| CVE-2024-29029 | Med | 0.33 | 6.1 | 0.01 | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the… | ||
| CVE-2024-29030 | Med | 0.31 | 5.8 | 0.01 | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file. | ||
| CVE-2024-29028 | Med | 0.31 | 5.8 | 0.01 | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1. | ||
| CVE-2022-4848 | Med | 0.30 | 5.7 | 0.01 | Dec 29, 2022 | Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. | ||
| CVE-2025-65798 | Med | 0.28 | 5.4 | 0.00 | Dec 8, 2025 | Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users. | ||
| CVE-2025-56760 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2025 | When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server. | ||
| CVE-2023-0109 | Med | 0.28 | 5.4 | 0.00 | Nov 15, 2024 | A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious… | ||
| CVE-2022-25978 | Med | 0.28 | 5.4 | 0.01 | Feb 15, 2023 | All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme. | ||
| CVE-2023-0112 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. | ||
| CVE-2023-0111 | Med | 0.28 | 5.4 | 0.01 | Jan 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. |
- risk 0.57cvss 9.8epss 0.00
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's…
- risk 0.57cvss 9.8epss 0.02
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the…
- risk 0.57cvss 9.8epss 0.03
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
- risk 0.57cvss 9.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.57cvss 9.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.55cvss 8.5epss 0.00
Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather…
- risk 0.55cvss 8.5epss 0.00
Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in…
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.52cvss 9.0epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
- risk 0.50cvss 8.8epss 0.01
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.50cvss 8.8epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.00
Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.50cvss 8.8epss 0.01
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.50cvss 8.8epss 0.01
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.49cvss 7.5epss 0.00
Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their password, the existing list of Access Tokens stay valid instead of expiring. If a user finds that their account has been compromised,…
- risk 0.48cvss 8.5epss 0.00
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.
- risk 0.47cvss 8.3epss 0.01
Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.
- risk 0.46cvss 8.1epss 0.01
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request,…
- risk 0.46cvss 8.1epss 0.01
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.46cvss 8.1epss 0.01
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.46cvss 8.1epss 0.01
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.42cvss 7.5epss 0.00
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
- risk 0.42cvss 7.5epss 0.01
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
- risk 0.42cvss 7.5epss 0.01
Denial of Service in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).
- risk 0.35cvss 5.4epss 0.00
Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their…
- risk 0.35cvss 6.5epss 0.01
Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.01
Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.01
Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.35cvss 6.5epss 0.00
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.
- risk 0.33cvss 6.1epss 0.00
Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages
- risk 0.33cvss 6.1epss 0.01
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the…
- risk 0.31cvss 5.8epss 0.01
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.
- risk 0.31cvss 5.8epss 0.01
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.
- risk 0.30cvss 5.7epss 0.01
Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
- risk 0.28cvss 5.4epss 0.00
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
- risk 0.28cvss 4.3epss 0.00
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.
- risk 0.28cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is accessed, the malicious…
- risk 0.28cvss 5.4epss 0.01
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Page 1 of 2