VendorsUsememosmemosany version
Vulnerabilities

Usememos Memos any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

64CVEs
CVE-2025-50738
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or interaction beyond viewing the memo. This can be exploited by an attacker to disclose the viewing user's IP address, browser User-Agent string, and potentially other request-specific information to the attacker-controlled server, leading to information disclosure and user tracking.
Published 2025-07-29 · Modified
9.8EPSS 0.021
CVE-2023-4696
Improper Access Control in usememos/memos
Published 2023-09-01 · Modified
9.8EPSS 0.011
CVE-2022-4866
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-31 · Modified
9.8EPSS 0.010
CVE-2022-4851
Improper Handling of Values in usememos/memos
Published 2022-12-29 · Modified
9.8EPSS 0.008
CVE-2022-4686
Authorization Bypass Through User-Controlled Key in usememos/memos
Published 2022-12-23 · Modified
9.8EPSS 0.007
CVE-2022-4797
Improper Restriction of Excessive Authentication Attempts in usememos/memos
Published 2022-12-28 · Modified
9.8EPSS 0.007
CVE-2022-4802
Authorization Bypass Through User-Controlled Key in usememos/memos
Published 2022-12-28 · Modified
9.1EPSS 0.006
CVE-2022-4865
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-31 · Modified
9.0EPSS 0.010
CVE-2023-0106
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2023-01-07 · Modified
9.0EPSS 0.006
CVE-2022-4809
Improper Access Control in usememos/memos
Published 2022-12-28 · Modified
8.8EPSS 0.009
CVE-2023-4697
Improper Privilege Management in usememos/memos
Published 2023-09-01 · Modified
8.8EPSS 0.008
CVE-2022-4803
Authorization Bypass Through User-Controlled Key in usememos/memos
Published 2022-12-28 · Modified
8.8EPSS 0.008
CVE-2022-4689
Improper Access Control in usememos/memos
Published 2022-12-23 · Modified
8.8EPSS 0.007
CVE-2022-4688
Improper Authorization in usememos/memos
Published 2022-12-23 · Modified
8.8EPSS 0.007
CVE-2022-4684
Improper Access Control in usememos/memos
Published 2022-12-23 · Modified
8.8EPSS 0.006
CVE-2022-4808
Improper Privilege Management in usememos/memos
Published 2022-12-28 · Modified
8.8EPSS 0.004
CVE-2023-5036
Cross-Site Request Forgery (CSRF) in usememos/memos
Published 2023-09-18 · Modified
8.8EPSS 0.003
CVE-2022-4844
Cross-Site Request Forgery (CSRF) in usememos/memos
Published 2022-12-29 · Modified
8.8EPSS 0.003
CVE-2022-4799
Authorization Bypass Through User-Controlled Key in usememos/memos
Published 2022-12-28 · Modified
8.6EPSS 0.008
CVE-2022-4798
Authorization Bypass Through User-Controlled Key in usememos/memos
Published 2022-12-28 · Modified
8.6EPSS 0.007
CVE-2022-4841
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-29 · Modified
8.6EPSS 0.006
CVE-2022-4800
Improper Verification of Source of a Communication Channel in usememos/memos
Published 2022-12-28 · Modified
8.6EPSS 0.006
CVE-2022-4812
Authorization Bypass Through User-Controlled Key in usememos/memos
Published 2022-12-28 · Modified
8.6EPSS 0.006
CVE-2022-4813
Insufficient Granularity of Access Control in usememos/memos
Published 2022-12-28 · Modified
8.6EPSS 0.005
CVE-2022-4814
Improper Access Control in usememos/memos
Published 2022-12-28 · Modified
8.6EPSS 0.005
CVE-2022-4848
Improper Verification of Source of a Communication Channel in usememos/memos
Published 2022-12-29 · Modified
8.6EPSS 0.005
CVE-2022-4863
Improper Handling of Insufficient Permissions or Privileges in usememos/memos
Published 2022-12-30 · Modified
8.4EPSS 0.007
CVE-2022-4691
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-23 · Modified
8.3EPSS 0.007
CVE-2022-4847
Incorrectly Specified Destination in a Communication Channel in usememos/memos
Published 2022-12-29 · Modified
8.3EPSS 0.006
CVE-2022-4811
Authorization Bypass Through User-Controlled Key in usememos/memos
Published 2022-12-28 · Modified
8.3EPSS 0.006
CVE-2022-4849
Cross-Site Request Forgery (CSRF) in usememos/memos
Published 2022-12-29 · Modified
8.3EPSS 0.003
CVE-2022-4806
Authorization Bypass Through User-Controlled Key in usememos/memos
Published 2022-12-28 · Modified
8.2EPSS 0.008
CVE-2022-4801
Insufficient Granularity of Access Control in usememos/memos
Published 2022-12-28 · Modified
8.2EPSS 0.007
CVE-2022-4804
Improper Authorization in usememos/memos
Published 2022-12-28 · Modified
8.2EPSS 0.006
CVE-2022-4807
Improper Access Control in usememos/memos
Published 2022-12-28 · Modified
8.2EPSS 0.006
CVE-2022-4734
Improper Removal of Sensitive Information Before Storage or Transfer in usememos/memos
Published 2022-12-25 · Modified
8.1EPSS 0.008
CVE-2022-4796
Incorrect Use of Privileged APIs in usememos/memos
Published 2022-12-28 · Modified
8.1EPSS 0.008
CVE-2024-41659
GHSL-2024-034: memos CORS Misconfiguration in server.go
Published 2024-08-20 · Analyzed
8.1EPSS 0.006
CVE-2022-4687
Incorrect Use of Privileged APIs in usememos/memos
Published 2022-12-23 · Modified
8.1EPSS 0.006
CVE-2022-4839
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-29 · Modified
8.0EPSS 0.008
1 / 2Next →