📦 Memos

by Usememos

🔍 What is Memos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-22952

CRITICAL CVSS 9.8 Feb 27, 2025

CVE-2025-22952 is a Server-Side Request Forgery (SSRF) vulnerability in elestio memos v0.23.0 that allows attackers to make unauthorized requests from the server to internal or external systems. This ...

CVE-2023-4696

CRITICAL CVSS 9.8 Sep 1, 2023

CVE-2023-4696 is an improper access control vulnerability in the memos self-hosted note-taking software that allows unauthenticated attackers to bypass authentication and access sensitive data. This a...

CVE-2025-65795

HIGH CVSS 7.5 Dec 8, 2025

This vulnerability allows unauthenticated attackers to create arbitrary user accounts in usememos memos v0.25.2 by exploiting incorrect access control in the /api/v1/user endpoint. Any organization ru...

CVE-2024-21635

HIGH CVSS 7.5 Nov 14, 2025

This vulnerability in Memos note-taking service allows attackers to maintain access to compromised accounts even after users change their passwords. Access tokens created before password changes remai...

CVE-2023-5036

HIGH CVSS 8.8 Sep 18, 2023

This CSRF vulnerability in the memos application allows attackers to trick authenticated users into performing unintended actions by crafting malicious requests. It affects all users running memos ver...

CVE-2023-4698

HIGH CVSS 7.5 Sep 1, 2023

This CVE describes an improper input validation vulnerability in the memos application that allows attackers to inject malicious input through user-controlled parameters. It affects all users running ...

CVE-2025-65797

MEDIUM CVSS 6.5 Dec 8, 2025

This vulnerability allows attackers with low-level privileges in usememos memos v0.25.2 to modify or delete identity providers, potentially leading to account takeover or denial of service. Any organi...

CVE-2025-65799

MEDIUM CVSS 4.3 Dec 8, 2025

CVE-2025-65799 is a path traversal vulnerability in usememos memos v0.25.2 that allows attackers to access files outside the intended directory through the Attachment service. This affects all deploym...

CVE-2025-65796

MEDIUM CVSS 4.3 Dec 8, 2025

CVE-2025-65796 is an improper access control vulnerability in usememos memos v0.25.2 that allows authenticated users with low-level privileges to delete reactions (likes, comments, etc.) on other user...

CVE-2025-65798

MEDIUM CVSS 5.4 Dec 8, 2025

An incorrect access control vulnerability in usememos memos v0.25.2 allows authenticated users with low-level privileges to modify or delete attachments uploaded by other users. This affects all deplo...

CVE-2025-56760

MEDIUM CVSS 4.3 Sep 3, 2025

This vulnerability allows attackers to write arbitrary files to the server when Memos 0.22 is configured with local storage. Attackers can exploit the CreateResource endpoint using path traversal sequ...

CVE-2025-56761

MEDIUM CVSS 5.4 Sep 3, 2025

Memos 0.22 has a stored XSS vulnerability in upload attachment and user avatar features where uploaded content isn't validated before being served back. Authenticated attackers can inject malicious sc...