CVE Tools

Github.com/usememos/memos

73 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Github.com/usememos/memos, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Github.com/usememos/memos CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Github.com/usememos/memos CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-021
2025-030
2025-040
2025-050
2025-060
2025-071
2025-080
2025-092
2025-100
2025-111
2025-125
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 73 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical68%
  • High1825%
  • Medium4967%

Latest CVEs

The 15 most recently published vulnerabilities affecting Github.com/usememos/memos.

  1. CVE-2025-65798Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.5.4
  2. CVE-2025-65799A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.4.3
  3. CVE-2025-65796Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.4.3
  4. CVE-2025-65797Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading...6.5
  5. CVE-2025-65795Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.7.5
  6. CVE-2024-21635Memos Access Tokens Stay Valid after User Password Change7.5
  7. CVE-2025-56761Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serv...5.4
  8. CVE-2025-56760When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write...4.3
  9. CVE-2025-50738The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches...9.8
  10. CVE-2025-22952elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.9.8
  11. CVE-2023-0109Stored XSS in usememos/memos5.4
  12. CVE-2024-41659GHSL-2024-034: memos CORS Misconfiguration in server.go8.1
  13. CVE-2024-29029memos vulnerable to an SSRF in /o/get/image6.1
  14. CVE-2024-29028memos vulnerable to an SSRF in /o/get/httpmeta5.8
  15. CVE-2024-29030memos vulnerable to an SSRF in /api/resource5.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store