Usememos maintains a focused note-taking and memo application that has achieved considerable prominence in the vulnerability landscape despite a narrow product footprint. The vendor's vulnerability exposure concentrates in its single Memos product and recurs consistently through application-layer weakness classes including cross-site scripting, improper access control, authorization bypass, cross-site request forgery, and server-side request forgery—a pattern reflective of web-application input handling and session-management challenges. Vulnerabilities affecting the vendor reach a meaningful share of serious severity outcomes and exhibit a moderate tendency toward public exploit availability. Defenders should prioritize updates to this product given its deployment footprint and the prevalence of exploitable web-application classes; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Usememos over time
Signals from CVEs in this vendor scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50738CRITICAL The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser auto | Jul 29, 2025 | 9.8 | 44 | NO | YES |
CVE-2025-22952CRITICAL elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. | Feb 27, 2025 | 9.8 | 39 | NO | YES |
CVE-2023-4696CRITICAL Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. | Sep 1, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-4686CRITICAL Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0. | Dec 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-4865CRITICAL Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | Dec 31, 2022 | 9.0 | 29 | NO | NO |
CVE-2022-4866CRITICAL Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | Dec 31, 2022 | 9.0 | 28 | NO | NO |
CVE-2022-4844HIGH Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | Dec 29, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-4809HIGH Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | Dec 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-4808HIGH Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1. | Dec 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-4689HIGH Improper Access Control in GitHub repository usememos/memos prior to 0.9.0. | Dec 23, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (73 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Usememos.
Media articles that mention a CVE ID that affects a product developed by Usememos — matched by CVE ID, not by vendor name.