Usememos

Memos

79 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.05%
  • Veröffentlicht 19.04.2024 15:15:50
  • Zuletzt bearbeitet 07.07.2025 16:03:50

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vul...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 18.09.2023 06:15:08
  • Zuletzt bearbeitet 21.11.2024 08:40:56

Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

Exploit
  • EPSS 0.76%
  • Veröffentlicht 01.09.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:42

Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 01.09.2023 01:15:09
  • Zuletzt bearbeitet 21.11.2024 08:35:42

Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

  • EPSS 0.9%
  • Veröffentlicht 01.09.2023 01:15:08
  • Zuletzt bearbeitet 21.11.2024 08:35:42

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

Exploit
  • EPSS 0.53%
  • Veröffentlicht 15.02.2023 05:15:11
  • Zuletzt bearbeitet 18.03.2025 16:15:12

All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 07.01.2023 04:15:08
  • Zuletzt bearbeitet 21.11.2024 07:36:34

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Exploit
  • EPSS 0.65%
  • Veröffentlicht 07.01.2023 04:15:08
  • Zuletzt bearbeitet 21.11.2024 07:36:33

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 07.01.2023 04:15:08
  • Zuletzt bearbeitet 21.11.2024 07:36:33

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 07.01.2023 04:15:08
  • Zuletzt bearbeitet 21.11.2024 07:36:34

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.