Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Usememos

First CVE: Dec 19, 2022Active for: 4 yearsTotal CVEs: 73
40.4
VTI Score
High

Usememos maintains a focused note-taking and memo application that has achieved considerable prominence in the vulnerability landscape despite a narrow product footprint. The vendor's vulnerability exposure concentrates in its single Memos product and recurs consistently through application-layer weakness classes including cross-site scripting, improper access control, authorization bypass, cross-site request forgery, and server-side request forgery—a pattern reflective of web-application input handling and session-management challenges. Vulnerabilities affecting the vendor reach a meaningful share of serious severity outcomes and exhibit a moderate tendency toward public exploit availability. Defenders should prioritize updates to this product given its deployment footprint and the prevalence of exploitable web-application classes; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
73
Total CVEs
More Total CVEs than 99% of tracked vendors
18.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Usememos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2022
3 years ago
Most Recent CVE
Dec 8, 2025
228 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (73 CVEs).

73 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-50738CRITICAL
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser auto
Jul 29, 20259.844NOYES
CVE-2025-22952CRITICAL
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.
Feb 27, 20259.839NOYES
CVE-2023-4696CRITICAL
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
Sep 1, 20239.830NONO
CVE-2022-4686CRITICAL
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
Dec 23, 20229.830NONO
CVE-2022-4865CRITICAL
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
Dec 31, 20229.029NONO
CVE-2022-4866CRITICAL
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
Dec 31, 20229.028NONO
CVE-2022-4844HIGH
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
Dec 29, 20228.828NONO
CVE-2022-4809HIGH
Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
Dec 28, 20228.828NONO
CVE-2022-4808HIGH
Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
Dec 28, 20228.828NONO
CVE-2022-4689HIGH
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
Dec 23, 20228.828NONO
View all 73 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products73 CVEs
70%
22%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network73 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low73 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None42 (57.5%)
Unknown0 (0.0%)
Required31 (42.5%)
Privileges Required
Low45 (61.6%)
High1 (1.4%)
None27 (37.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (73 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
6.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Usememos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Usememos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Usememos's Products

View all 4 CNAs →

Top CWEs