CVE Tools

Memos

79 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Memos, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Memos CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Memos CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-021
2025-030
2025-040
2025-050
2025-060
2025-071
2025-080
2025-092
2025-100
2025-111
2025-125
2026-010
2026-020
2026-030
2026-041
2026-050
2026-060
2026-070
2026-084
2026-091

Severity

How the 79 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical79%
  • High2127%
  • Medium5165%

Latest CVEs

The 15 most recently published vulnerabilities affecting Memos.

  1. CVE-2026-84203Memos 0.26.0 through 0.30.0 Insufficient Session Expiration on Password Change8.1
  2. CVE-2026-82476Memos through 0.30.0 SSRF via Omitted CGNAT Address Range5.3
  3. CVE-2026-75110MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET9.8
  4. CVE-2026-71272Memos Webhook DNS Rebinding TOCTOU SSRF in safeDialContext()8.5
  5. CVE-2026-71271Memos Webhook SSRF via 0.0.0.0 Reserved-IP Bypass8.5
  6. CVE-2026-6634usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization6.3
  7. CVE-2025-65798Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.5.4
  8. CVE-2025-65799A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.4.3
  9. CVE-2025-65796Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.4.3
  10. CVE-2025-65797Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading...6.5
  11. CVE-2025-65795Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.7.5
  12. CVE-2024-21635Memos Access Tokens Stay Valid after User Password Change7.5
  13. CVE-2025-56761Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serv...5.4
  14. CVE-2025-56760When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write...4.3
  15. CVE-2025-50738The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches...9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store