Memos
Vendor:
First CVE: Dec 19, 2022 · Active for 3 years
73
Total CVEs
More Total CVEs than 99% of tracked products
18.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Memos over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2022
3 years ago
Most Recent CVE
Dec 8, 2025
229 days ago
CVE Severity & Scoring
Memos73 CVEs
70%
22%
8%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network73 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low73 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None42 (57.5%)
Unknown0 (0.0%)
Required31 (42.5%)
Privileges Required
Low45 (61.6%)
High1 (1.4%)
None27 (37.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50738CRITICAL The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing such an image, their browser auto | Jul 29, 2025 | 9.8 | 44 | NO | YES |
CVE-2025-22952CRITICAL elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks. | Feb 27, 2025 | 9.8 | 39 | NO | YES |
CVE-2023-4696CRITICAL Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. | Sep 1, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-4686CRITICAL Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0. | Dec 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-4865CRITICAL Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | Dec 31, 2022 | 9.0 | 29 | NO | NO |
CVE-2022-4866CRITICAL Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | Dec 31, 2022 | 9.0 | 28 | NO | NO |
CVE-2022-4844HIGH Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | Dec 29, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-4809HIGH Improper Access Control in GitHub repository usememos/memos prior to 0.9.1. | Dec 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-4808HIGH Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1. | Dec 28, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-4689HIGH Improper Access Control in GitHub repository usememos/memos prior to 0.9.0. | Dec 23, 2022 | 8.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (73 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
6.8% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (73 CVEs).
Media Mentions
Signals from CVEs in this product scope (73 CVEs).
Top CNAs Publishing CVEs For Memos
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9.1 | 1 | 5.4 | 0.4% | 0 | 0 |
| 0.25.2 | 5 | 5.6 | 0.2% | 0 | 0 |
| 0.23.0 | 1 | 9.8 | 2.8% | 0 | 1 |
| 0.22.0 | 2 | 4.8 | 0.3% | 0 | 0 |