Vulnerability index

Browse CVEs

62 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Memos HIGH 7.5
CVE-2025-65795

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a craf…

Patch available
Fix from $1,950 2025-12-08
Memos MEDIUM 6.5
CVE-2025-65797

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify …

Patch available
Fix from $1,600 2025-12-08
Memos MEDIUM 5.4
CVE-2025-65798

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by oth…

Patch available
Fix from $1,600 2025-12-08
Memos HIGH 7.5
CVE-2024-21635

Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their passw…

Fix: after 0.18.1
Fix from $1,950 2025-11-14
Memos MEDIUM 5.4
CVE-2025-56761

Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verif…

Patch available
Fix from $1,600 2025-09-03
Memos CRITICAL 9.8
CVE-2025-50738

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing su…

Fix: after 0.24.3
Fix from $2,300 2025-07-29
Memos CRITICAL 9.8
CVE-2025-22952

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploite…

Patch available
Fix from $2,300 2025-02-27
Memos MEDIUM 5.4
CVE-2023-0109

A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a J…

Patch available
Fix from $1,600 2024-11-15
Memos HIGH 8.1
CVE-2024-41659

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is re…

Fix: 0.21.0+
Fix from $1,950 2024-08-20
Memos MEDIUM 6.1
CVE-2024-29029

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthentica…

Fix: 0.22.0+
Fix from $1,600 2024-04-19
Memos MEDIUM 5.3
CVE-2024-29028

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthent…

Fix: 0.16.1+
Fix from $1,600 2024-04-19
Memos MEDIUM 5.3
CVE-2024-29030

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticat…

Fix: 0.22.0+
Fix from $1,600 2024-04-19
Memos HIGH 8.8
CVE-2023-5036

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

Fix: 0.15.1+
Fix from $1,950 2023-09-18
Memos HIGH 8.8
CVE-2023-4697

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

Fix: 0.13.2+
Fix from $1,950 2023-09-01
Memos HIGH 7.5
CVE-2023-4698

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

Fix: 0.13.2+
Fix from $1,950 2023-09-01
Memos CRITICAL 9.8
CVE-2023-4696

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

Fix: 0.13.2+
Fix from $2,300 2023-09-01
Memos MEDIUM 6.1
CVE-2022-25978

All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external reso…

Patch available
Fix from $1,600 2023-02-15
Memos MEDIUM 5.4
CVE-2023-0106

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Fix: 0.10.0+
Fix from $1,600 2023-01-07
Memos MEDIUM 5.4
CVE-2023-0107

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Fix: 0.10.0+
Fix from $1,600 2023-01-07
Memos MEDIUM 5.4
CVE-2023-0108

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Fix: 0.10.0+
Fix from $1,600 2023-01-07
Memos MEDIUM 5.4
CVE-2023-0110

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Fix: 0.10.0+
Fix from $1,600 2023-01-07
Memos MEDIUM 5.4
CVE-2023-0111

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Fix: 0.10.0+
Fix from $1,600 2023-01-07
Memos MEDIUM 5.4
CVE-2023-0112

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Fix: 0.10.0+
Fix from $1,600 2023-01-07
Memos CRITICAL 9.0
CVE-2022-4866

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $2,300 2022-12-31
Memos CRITICAL 9.0
CVE-2022-4865

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $2,300 2022-12-31
Memos MEDIUM 6.5
CVE-2022-4863

Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-30
Memos HIGH 8.8
CVE-2022-4844

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,950 2022-12-29
Memos MEDIUM 6.5
CVE-2022-4846

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-29
Memos MEDIUM 6.5
CVE-2022-4847

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-29
Memos MEDIUM 6.5
CVE-2022-4849

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.

Fix: 0.9.1+
Fix from $1,600 2022-12-29