usememos records
73 published records for vendor usememos.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 93.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-284 Improper Access Control11
- CWE-639 Authorization Bypass Through User-Controlled Key8
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-648 Incorrect Use of Privileged APIs3
- CWE-918 Server-Side Request Forgery (SSRF)3
The weakness classes this vendor ships most often: where to look.
CWEAll records
73 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-22952Proof of concept | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can beusememos · memos · CWE-918 | Critical9.8 | — | 2.9% | Feb 27, 2025 |
40Plan | CVE-2025-50738Proof of concept | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs.usememos · memos · CWE-200 | Critical9.8 | — | 2.2% | Jul 29, 2025 |
39Monitor | CVE-2023-4696Proof of concept | Improper Access Control in usememos/memosusememos · memos · CWE-284 | Critical9.8 | — | 1.1% | Aug 31, 2023 |
39Monitor | CVE-2022-4686No exploit | Authorization Bypass Through User-Controlled Key in usememos/memosusememos · memos · CWE-639 | Critical9.8 | — | 0.7% | Dec 23, 2022 |
36Monitor | CVE-2022-4865No exploit | Cross-site Scripting (XSS) - Stored in usememos/memosusememos · memos · CWE-79 | Critical9.0 | — | 1.0% | Dec 31, 2022 |
36Monitor | CVE-2022-4866No exploit | Cross-site Scripting (XSS) - Stored in usememos/memosusememos · memos · CWE-79 | Critical9.0 | — | 1.0% | Dec 31, 2022 |
35Monitor | CVE-2022-4809No exploit | Improper Access Control in usememos/memosusememos · memos · CWE-284 | High8.8 | — | 0.9% | Dec 28, 2022 |
35Monitor | CVE-2023-4697No exploit | Improper Privilege Management in usememos/memosusememos · memos · CWE-269 | High8.8 | — | 0.8% | Aug 31, 2023 |
35Monitor | CVE-2022-4803No exploit | Authorization Bypass Through User-Controlled Key in usememos/memosusememos · memos · CWE-639 | High8.8 | — | 0.8% | Dec 28, 2022 |
35Monitor | CVE-2022-4688No exploit | Improper Authorization in usememos/memosusememos · memos · CWE-285 | High8.8 | — | 0.7% | Dec 23, 2022 |
35Monitor | CVE-2022-4689No exploit | Improper Access Control in usememos/memosusememos · memos · CWE-284 | High8.8 | — | 0.7% | Dec 23, 2022 |
35Monitor | CVE-2022-4684No exploit | Improper Access Control in usememos/memosusememos · memos · CWE-284 | High8.8 | — | 0.6% | Dec 23, 2022 |
35Monitor | CVE-2022-4808No exploit | Improper Privilege Management in usememos/memosusememos · memos · CWE-269 | High8.8 | — | 0.4% | Dec 28, 2022 |
35Monitor | CVE-2023-5036No exploit | Cross-Site Request Forgery (CSRF) in usememos/memosusememos · memos · CWE-352 | High8.8 | — | 0.3% | Sep 18, 2023 |
35Monitor | CVE-2022-4844No exploit | Cross-Site Request Forgery (CSRF) in usememos/memosusememos · memos · CWE-352 | High8.8 | — | 0.3% | Dec 29, 2022 |
32Monitor | CVE-2022-4796No exploit | Incorrect Use of Privileged APIs in usememos/memosusememos · memos · CWE-648 | High8.1 | — | 0.8% | Dec 28, 2022 |
32Monitor | CVE-2024-41659No exploit | GHSL-2024-034: memos CORS Misconfiguration in server.gousememos · memos · CWE-942 | High8.1 | — | 0.6% | Aug 20, 2024 |
32Monitor | CVE-2022-4687No exploit | Incorrect Use of Privileged APIs in usememos/memosusememos · memos · CWE-648 | High8.1 | — | 0.6% | Dec 23, 2022 |
30Monitor | CVE-2023-4698Proof of concept | Improper Input Validation in usememos/memosusememos · memos · CWE-20 | High7.5 | — | 0.9% | Aug 31, 2023 |
30Monitor | CVE-2022-4767No exploit | Denial of Service in usememos/memosusememos · memos · CWE-400 | High7.5 | — | 0.7% | Dec 27, 2022 |
30Monitor | CVE-2025-65795No exploit | Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts vusememos · memos · CWE-284 | High7.5 | — | 0.3% | Dec 8, 2025 |
28Monitor | CVE-2024-21635No exploit | Memos Access Tokens Stay Valid after User Password Changeusememos · memos · CWE-287 | High7.1 | — | 0.3% | Nov 14, 2025 |
26Monitor | CVE-2022-4799No exploit | Authorization Bypass Through User-Controlled Key in usememos/memosusememos · memos · CWE-639 | Medium6.5 | — | 0.8% | Dec 28, 2022 |
26Monitor | CVE-2022-4863No exploit | Improper Handling of Insufficient Permissions or Privileges in usememos/memosusememos · memos · CWE-280 | Medium6.5 | — | 0.7% | Dec 30, 2022 |
26Monitor | CVE-2022-4847No exploit | Incorrectly Specified Destination in a Communication Channel in usememos/memosusememos · memos · CWE-941 | Medium6.5 | — | 0.6% | Dec 29, 2022 |
- CVE-2025-2295240Plan
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be
CriticalCVSS 9.8Proof of conceptEPSS 3%usememos · memosFeb 27, 2025
- CVE-2025-5073840Plan
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs.
CriticalCVSS 9.8Proof of conceptEPSS 2%usememos · memosJul 29, 2025
- CVE-2023-469639Monitor
Improper Access Control in usememos/memos
CriticalCVSS 9.8Proof of conceptEPSS 1%usememos · memosAug 31, 2023
- CVE-2022-468639Monitor
Authorization Bypass Through User-Controlled Key in usememos/memos
CriticalCVSS 9.8No exploitEPSS 1%usememos · memosDec 23, 2022
- CVE-2022-486536Monitor
Cross-site Scripting (XSS) - Stored in usememos/memos
CriticalCVSS 9.0No exploitEPSS 1%usememos · memosDec 31, 2022
- CVE-2022-486636Monitor
Cross-site Scripting (XSS) - Stored in usememos/memos
CriticalCVSS 9.0No exploitEPSS 1%usememos · memosDec 31, 2022
- CVE-2022-480935Monitor
Improper Access Control in usememos/memos
HighCVSS 8.8No exploitEPSS 1%usememos · memosDec 28, 2022
- CVE-2023-469735Monitor
Improper Privilege Management in usememos/memos
HighCVSS 8.8No exploitEPSS 1%usememos · memosAug 31, 2023
- CVE-2022-480335Monitor
Authorization Bypass Through User-Controlled Key in usememos/memos
HighCVSS 8.8No exploitEPSS 1%usememos · memosDec 28, 2022
- CVE-2022-468835Monitor
Improper Authorization in usememos/memos
HighCVSS 8.8No exploitEPSS 1%usememos · memosDec 23, 2022
- CVE-2022-468935Monitor
Improper Access Control in usememos/memos
HighCVSS 8.8No exploitEPSS 1%usememos · memosDec 23, 2022
- CVE-2022-468435Monitor
Improper Access Control in usememos/memos
HighCVSS 8.8No exploitEPSS 1%usememos · memosDec 23, 2022
- CVE-2022-480835Monitor
Improper Privilege Management in usememos/memos
HighCVSS 8.8No exploitEPSS 0%usememos · memosDec 28, 2022
- CVE-2023-503635Monitor
Cross-Site Request Forgery (CSRF) in usememos/memos
HighCVSS 8.8No exploitEPSS 0%usememos · memosSep 18, 2023
- CVE-2022-484435Monitor
Cross-Site Request Forgery (CSRF) in usememos/memos
HighCVSS 8.8No exploitEPSS 0%usememos · memosDec 29, 2022
- CVE-2022-479632Monitor
Incorrect Use of Privileged APIs in usememos/memos
HighCVSS 8.1No exploitEPSS 1%usememos · memosDec 28, 2022
- CVE-2024-4165932Monitor
GHSL-2024-034: memos CORS Misconfiguration in server.go
HighCVSS 8.1No exploitEPSS 1%usememos · memosAug 20, 2024
- CVE-2022-468732Monitor
Incorrect Use of Privileged APIs in usememos/memos
HighCVSS 8.1No exploitEPSS 1%usememos · memosDec 23, 2022
- CVE-2023-469830Monitor
Improper Input Validation in usememos/memos
HighCVSS 7.5Proof of conceptEPSS 1%usememos · memosAug 31, 2023
- CVE-2022-476730Monitor
Denial of Service in usememos/memos
HighCVSS 7.5No exploitEPSS 1%usememos · memosDec 27, 2022
- CVE-2025-6579530Monitor
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts v
HighCVSS 7.5No exploitEPSS 0%usememos · memosDec 8, 2025
- CVE-2024-2163528Monitor
Memos Access Tokens Stay Valid after User Password Change
HighCVSS 7.1No exploitEPSS 0%usememos · memosNov 14, 2025
- CVE-2022-479926Monitor
Authorization Bypass Through User-Controlled Key in usememos/memos
MediumCVSS 6.5No exploitEPSS 1%usememos · memosDec 28, 2022
- CVE-2022-486326Monitor
Improper Handling of Insufficient Permissions or Privileges in usememos/memos
MediumCVSS 6.5No exploitEPSS 1%usememos · memosDec 30, 2022
- CVE-2022-484726Monitor
Incorrectly Specified Destination in a Communication Channel in usememos/memos
MediumCVSS 6.5No exploitEPSS 1%usememos · memosDec 29, 2022