Usememos
57 CVEs tracked since 2022. Since Dec 2022, none of them reached CISA KEV.
Usememos CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-12 | 47 | 0 |
| 2023-01 | 6 | 0 |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | 4 | 0 |
Products
The products that kept showing up in Usememos's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Usememos.
- CVE-2026-84203Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change8.1
- CVE-2026-82476Memos through 0.30.0 SSRF via Omitted CGNAT Address Range5.3
- CVE-2026-71272Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext()8.5
- CVE-2026-71271Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass8.5
- CVE-2026-6634usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization6.3
- CVE-2025-65798Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.5.4
- CVE-2025-65799A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.4.3
- CVE-2025-65796Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.4.3
- CVE-2025-65797Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading...6.5
- CVE-2025-65795Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.7.5
- CVE-2024-21635Memos Access Tokens Stay Valid after User Password Change7.5
- CVE-2025-56761Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serv...5.4
- CVE-2025-56760When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write...4.3
- CVE-2025-50738The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches...9.8
- CVE-2025-22952elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.9.8
The record
- Peak rank
- #24 in Dec 2022
- Busiest month shown
- Dec 2022, 47 CVEs
- Months with a KEV entry
- 0 since Dec 2022
- Monthly snapshots
- 3 since 2022