Usememos / Memos
78 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84203 | Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change | HIGH | 8.6 | Sep 1, 2026 |
| CVE-2026-82476 | Memos through 0.30.0 SSRF via Omitted CGNAT Address Range | MEDIUM | 6.9 | Aug 29, 2026 |
| CVE-2026-71272 | Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext() | HIGH | 8.5 | Aug 5, 2026 |
| CVE-2026-71271 | Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass | HIGH | 8.5 | Aug 5, 2026 |
| CVE-2026-6634 | usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization | MEDIUM | 5.3 | Apr 20, 2026 |
| CVE-2025-65799 | A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal. | MEDIUM | 4.3 | Dec 8, 2025 |
| CVE-2025-65798 | Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users. | MEDIUM | 5.4 | Dec 8, 2025 |
| CVE-2025-65797 | Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete… | MEDIUM | 6.5 | Dec 8, 2025 |
| CVE-2025-65796 | Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos. | MEDIUM | 4.3 | Dec 8, 2025 |
| CVE-2025-65795 | Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted reques… | HIGH | 7.5 | Dec 8, 2025 |
| CVE-2024-21635 | Memos Access Tokens Stay Valid after User Password Change | HIGH | 7.1 | Nov 14, 2025 |
| CVE-2025-56761 | Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the cont… | MEDIUM | 5.4 | Sep 3, 2025 |
| CVE-2025-56760 | When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in t… | MEDIUM | 4.3 | Sep 3, 2025 |
| CVE-2025-50738 | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an imag… | MEDIUM | 5.2 | Jul 29, 2025 |
| CVE-2025-22952 | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perfo… | MEDIUM | 6.9 | Feb 27, 2025 |
| CVE-2023-0109 | Stored XSS in usememos/memos | MEDIUM | 5.4 | Nov 15, 2024 |
| CVE-2024-41659 | GHSL-2024-034: memos CORS Misconfiguration in server.go | HIGH | 8.6 | Aug 20, 2024 |
| CVE-2024-29029 | memos vulnerable to an SSRF in /o/get/image | MEDIUM | 6.9 | Apr 19, 2024 |
| CVE-2024-29028 | memos vulnerable to an SSRF in /o/get/httpmeta | MEDIUM | 5.8 | Apr 19, 2024 |
| CVE-2024-29030 | memos vulnerable to an SSRF in /api/resource | MEDIUM | 6.9 | Apr 19, 2024 |
| CVE-2023-5036 | Cross-Site Request Forgery (CSRF) in usememos/memos | HIGH | 8.8 | Sep 18, 2023 |
| CVE-2023-4697 | Improper Privilege Management in usememos/memos | HIGH | 8.8 | Sep 1, 2023 |
| CVE-2023-4698 | Improper Input Validation in usememos/memos | HIGH | 7.5 | Sep 1, 2023 |
| CVE-2023-4696 | Improper Access Control in usememos/memos | CRITICAL | 9.8 | Sep 1, 2023 |
| CVE-2022-25978 | All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, whi… | MEDIUM | 6.1 | Feb 15, 2023 |
Showing 1 to 25 of 78 CVEs