VendorsUsememosmemosall versions
Vulnerabilities

Usememos Memos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

73CVEs
CVE-2022-4687
Incorrect Use of Privileged APIs in usememos/memos
Published 2022-12-23 · Modified
8.1EPSS 0.006
CVE-2022-4839
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-29 · Modified
8.0EPSS 0.008
CVE-2022-4609
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-19 · Modified
7.6EPSS 0.007
CVE-2022-4767
Denial of Service in usememos/memos
Published 2022-12-27 · Modified
7.6EPSS 0.007
CVE-2022-4840
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-29 · Modified
7.6EPSS 0.007
CVE-2022-4695
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-23 · Modified
7.6EPSS 0.007
CVE-2023-0112
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2023-01-07 · Modified
7.6EPSS 0.006
CVE-2023-4698
Improper Input Validation in usememos/memos
Published 2023-09-01 · Modified
7.5EPSS 0.009
CVE-2024-21635
Memos Access Tokens Stay Valid after User Password Change
Published 2025-11-14 · Analyzed
7.5EPSS 0.003
CVE-2025-65795
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
Published 2025-12-08 · Modified
7.5EPSS 0.003
CVE-2022-4805
Incorrect Use of Privileged APIs in usememos/memos
Published 2022-12-28 · Modified
7.3EPSS 0.005
CVE-2022-4690
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-23 · Modified
7.1EPSS 0.006
CVE-2022-4692
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-23 · Modified
7.1EPSS 0.006
CVE-2023-0108
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2023-01-07 · Modified
7.1EPSS 0.005
CVE-2023-0110
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2023-01-07 · Modified
7.1EPSS 0.005
CVE-2022-4845
Cross-Site Request Forgery (CSRF) in usememos/memos
Published 2022-12-29 · Modified
6.7EPSS 0.003
CVE-2023-0107
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2023-01-07 · Modified
6.5EPSS 0.005
CVE-2022-4683
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in usememos/memos
Published 2022-12-23 · Modified
6.5EPSS 0.004
CVE-2022-4850
Cross-Site Request Forgery (CSRF) in usememos/memos
Published 2022-12-29 · Modified
6.5EPSS 0.003
CVE-2025-65797
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Service (DoS).
Published 2025-12-08 · Modified
6.5EPSS 0.003
CVE-2022-4846
Cross-Site Request Forgery (CSRF) in usememos/memos
Published 2022-12-29 · Modified
6.5EPSS 0.003
CVE-2022-4810
Improper Access Control in usememos/memos
Published 2022-12-28 · Modified
6.3EPSS 0.005
CVE-2024-29029
memos vulnerable to an SSRF in /o/get/image
Published 2024-04-19 · Analyzed
6.1EPSS 0.011
CVE-2022-25978
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
Published 2023-02-15 · Modified
6.1EPSS 0.005
CVE-2024-29030
memos vulnerable to an SSRF in /api/resource
Published 2024-04-19 · Analyzed
5.8EPSS 0.011
CVE-2024-29028
memos vulnerable to an SSRF in /o/get/httpmeta
Published 2024-04-19 · Analyzed
5.8EPSS 0.010
CVE-2022-4694
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2022-12-23 · Modified
5.7EPSS 0.005
CVE-2023-0111
Cross-site Scripting (XSS) - Stored in usememos/memos
Published 2023-01-07 · Modified
5.4EPSS 0.005
CVE-2025-56761
Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use this to elevate their privileges when the stored XSS is viewed by an admin.
Published 2025-09-03 · Analyzed
5.4EPSS 0.003
CVE-2025-65798
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
Published 2025-12-08 · Modified
5.4EPSS 0.002
CVE-2025-56760
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.
Published 2025-09-03 · Analyzed
4.3EPSS 0.004
CVE-2025-65799
A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.
Published 2025-12-08 · Modified
4.3EPSS 0.002
CVE-2025-65796
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.
Published 2025-12-08 · Modified
4.3EPSS 0.002
← Prev2 / 2