CVE Tools

Usememos

57 CVEs tracked since 2022. Since Dec 2022, none of them reached CISA KEV.

Usememos CVEs per month

Dec 2022 to Sep 2023. Point at a month, or focus the strip and use the arrow keys.
Usememos CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-12470
2023-0160
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-0940

Products

The products that kept showing up in Usememos's monthly top three, with their CVEs summed over those months.

  1. Memos573 months
  2. Usememos/memos573 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Usememos.

  1. CVE-2026-84203Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change8.1
  2. CVE-2026-82476Memos through 0.30.0 SSRF via Omitted CGNAT Address Range5.3
  3. CVE-2026-71272Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext()8.5
  4. CVE-2026-71271Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass8.5
  5. CVE-2026-6634usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization6.3
  6. CVE-2025-65798Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.5.4
  7. CVE-2025-65799A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.4.3
  8. CVE-2025-65796Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.4.3
  9. CVE-2025-65797Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading...6.5
  10. CVE-2025-65795Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.7.5
  11. CVE-2024-21635Memos Access Tokens Stay Valid after User Password Change7.5
  12. CVE-2025-56761Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serv...5.4
  13. CVE-2025-56760When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write...4.3
  14. CVE-2025-50738The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches...9.8
  15. CVE-2025-22952elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.9.8

The record

Peak rank
#24 in Dec 2022
Busiest month shown
Dec 2022, 47 CVEs
Months with a KEV entry
0 since Dec 2022
Monthly snapshots
3 since 2022
Usememos's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store