Product
usememos memos
73 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-65799
CVE-2025-65797
CVE-2025-65795
CVE-2025-65798
CVE-2025-65796
CVE-2024-21635
CVE-2025-56761
CVE-2025-56760
CVE-2025-50738
CVE-2025-22952
CVE-2023-0109
CVE-2024-41659
CVE-2024-29029
CVE-2024-29030
CVE-2024-29028
CVE-2023-5036
CVE-2023-4698
CVE-2023-4697
CVE-2023-4696
CVE-2022-25978
CVE-2023-0112
CVE-2023-0111
CVE-2023-0110
CVE-2023-0108
CVE-2023-0107
CVE-2023-0106
CVE-2022-4866
CVE-2022-4865
CVE-2022-4863
CVE-2022-4851
CVE-2022-4850
CVE-2022-4849
CVE-2022-4848
CVE-2022-4847
CVE-2022-4846
CVE-2022-4845
CVE-2022-4844
CVE-2022-4841
CVE-2022-4840
CVE-2022-4839
CVE-2022-4814
CVE-2022-4813
CVE-2022-4812
CVE-2022-4811
CVE-2022-4810
CVE-2022-4809
CVE-2022-4808
CVE-2022-4807
CVE-2022-4806
CVE-2022-4805
CVE-2022-4804
CVE-2022-4803
CVE-2022-4802
CVE-2022-4801
CVE-2022-4800
CVE-2022-4799
CVE-2022-4798
CVE-2022-4797
CVE-2022-4796
CVE-2022-4767
CVE-2022-4734
CVE-2022-4695
CVE-2022-4694
CVE-2022-4691
CVE-2022-4692
CVE-2022-4690
CVE-2022-4689
CVE-2022-4688
CVE-2022-4687
CVE-2022-4686
CVE-2022-4684
CVE-2022-4683
CVE-2022-4609
all versions
A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a p
all versions
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to
all versions
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary
all versions
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete atta
all versions
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made
<= 0.18.1
Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user
all versions
Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. M
all versions
When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a
<= 0.24.3
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a
all versions
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, wh
all versions
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an att
< 0.21.0
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arb
< 0.22.0
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that
>= 0.13.2 and < 0.22.0
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that
>= 0.13.2 and < 0.16.1
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta th
< 0.15.1
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
< 0.13.2
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
< 0.13.2
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
< 0.13.2
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
all versions
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient chec
< 0.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
< 0.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
< 0.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
< 0.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
< 0.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
< 0.10.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
< 0.9.1
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before
< 0.9.1
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Authorization in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Denial of Service in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.1
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.
< 0.9.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.
< 0.9.0
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.