Usememos

Memos

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.12%
  • Veröffentlicht 15.11.2024 11:15:08
  • Zuletzt bearbeitet 19.11.2024 14:44:24

A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is ...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 20.08.2024 20:15:08
  • Zuletzt bearbeitet 10.07.2025 15:36:42

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to mak...

Exploit
  • EPSS 2.63%
  • Veröffentlicht 19.04.2024 16:15:09
  • Zuletzt bearbeitet 02.01.2025 20:46:24

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request ...

Exploit
  • EPSS 5.75%
  • Veröffentlicht 19.04.2024 15:15:50
  • Zuletzt bearbeitet 07.07.2025 16:05:52

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.

Exploit
  • EPSS 6.34%
  • Veröffentlicht 19.04.2024 15:15:50
  • Zuletzt bearbeitet 07.07.2025 16:03:50

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vul...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 18.09.2023 06:15:08
  • Zuletzt bearbeitet 21.11.2024 08:40:56

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 01.09.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:42

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

Exploit
  • EPSS 1.62%
  • Veröffentlicht 01.09.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:42

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

  • EPSS 1.25%
  • Veröffentlicht 01.09.2023 01:15:08
  • Zuletzt bearbeitet 21.11.2024 08:35:42

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 15.02.2023 05:15:11
  • Zuletzt bearbeitet 18.03.2025 16:15:12

All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.