Usememos

Memos

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.01%
  • Veröffentlicht 29.07.2025 00:00:00
  • Zuletzt bearbeitet 22.08.2025 16:15:43

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser automatically fetches the image URL without explicit user consent or inter...

Medienbericht Exploit
  • EPSS 2.82%
  • Veröffentlicht 27.02.2025 20:16:04
  • Zuletzt bearbeitet 10.07.2025 22:52:03

elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 15.11.2024 11:15:08
  • Zuletzt bearbeitet 19.11.2024 14:44:24

A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is ...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 20.08.2024 20:15:08
  • Zuletzt bearbeitet 10.07.2025 15:36:42

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to mak...

Exploit
  • EPSS 1.08%
  • Veröffentlicht 19.04.2024 16:15:09
  • Zuletzt bearbeitet 02.01.2025 20:46:24

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request ...

Exploit
  • EPSS 1.14%
  • Veröffentlicht 19.04.2024 15:15:50
  • Zuletzt bearbeitet 07.07.2025 16:05:52

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.

Exploit
  • EPSS 1.05%
  • Veröffentlicht 19.04.2024 15:15:50
  • Zuletzt bearbeitet 07.07.2025 16:03:50

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vul...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 18.09.2023 06:15:08
  • Zuletzt bearbeitet 21.11.2024 08:40:56

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

Exploit
  • EPSS 0.76%
  • Veröffentlicht 01.09.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:42

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 01.09.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:42

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.