CVE-2023-0109
- EPSS 0.12%
- Veröffentlicht 15.11.2024 11:15:08
- Zuletzt bearbeitet 19.11.2024 14:44:24
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and reference it in an HTML file. When the HTML file is ...
CVE-2024-41659
- EPSS 0.14%
- Veröffentlicht 20.08.2024 20:15:08
- Zuletzt bearbeitet 10.07.2025 15:36:42
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to mak...
CVE-2024-29029
- EPSS 2.63%
- Veröffentlicht 19.04.2024 16:15:09
- Zuletzt bearbeitet 02.01.2025 20:46:24
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request ...
CVE-2024-29030
- EPSS 5.75%
- Veröffentlicht 19.04.2024 15:15:50
- Zuletzt bearbeitet 07.07.2025 16:05:52
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.
CVE-2024-29028
- EPSS 6.34%
- Veröffentlicht 19.04.2024 15:15:50
- Zuletzt bearbeitet 07.07.2025 16:03:50
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vul...
CVE-2023-5036
- EPSS 0.08%
- Veröffentlicht 18.09.2023 06:15:08
- Zuletzt bearbeitet 21.11.2024 08:40:56
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
CVE-2023-4697
- EPSS 0.08%
- Veröffentlicht 01.09.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:42
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4698
- EPSS 1.62%
- Veröffentlicht 01.09.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:42
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4696
- EPSS 1.25%
- Veröffentlicht 01.09.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 08:35:42
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
CVE-2022-25978
- EPSS 0.11%
- Veröffentlicht 15.02.2023 05:15:11
- Zuletzt bearbeitet 18.03.2025 16:15:12
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.