Usememos

Memos

77 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.25%
  • Veröffentlicht 03.09.2025 00:00:00
  • Zuletzt bearbeitet 09.09.2025 18:27:28

Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verify the content type of the uploaded data and serve it back as is. An authenticated attacker can use th...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 03.09.2025 00:00:00
  • Zuletzt bearbeitet 09.09.2025 18:30:48

When Memos 0.22 is configured to store objects locally, an attacker can create a file via the CreateResource endpoint containing a path traversal sequence in the name, allowing arbitrary file write on the server.

Exploit
  • EPSS 2.08%
  • Veröffentlicht 29.07.2025 00:00:00
  • Zuletzt bearbeitet 22.08.2025 16:15:43

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or inter...

Medienbericht Exploit
  • EPSS 2.85%
  • Veröffentlicht 27.02.2025 20:16:04
  • Zuletzt bearbeitet 10.07.2025 22:52:03

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 15.11.2024 11:15:08
  • Zuletzt bearbeitet 19.11.2024 14:44:24

A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is ...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 20.08.2024 20:15:08
  • Zuletzt bearbeitet 10.07.2025 15:36:42

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to mak...

Exploit
  • EPSS 1.08%
  • Veröffentlicht 19.04.2024 16:15:09
  • Zuletzt bearbeitet 02.01.2025 20:46:24

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request ...

Exploit
  • EPSS 1.05%
  • Veröffentlicht 19.04.2024 15:15:50
  • Zuletzt bearbeitet 07.07.2025 16:03:50

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vul...

Exploit
  • EPSS 1.14%
  • Veröffentlicht 19.04.2024 15:15:50
  • Zuletzt bearbeitet 07.07.2025 16:05:52

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 18.09.2023 06:15:08
  • Zuletzt bearbeitet 21.11.2024 08:40:56

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.