VulnSea

memos vulnerabilities

CVEs whose affected-version data names the memos package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2025-65799Medium· 4.3
9mo ago

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

Sunlitusememos · memosEPSS 0.21%via NVD
CVE-2025-65797Medium· 6.5
9mo ago

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…

Sunlitusememos · memosEPSS 0.28%via NVD
CVE-2025-65795High· 7.5
9mo ago

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

Twilightusememos · memosEPSS 0.26%via NVD
CVE-2025-65798Medium· 5.4
9mo ago

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

Sunlitusememos · memosEPSS 0.18%via NVD
CVE-2025-65796Medium· 4.3
9mo ago

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

Sunlitusememos · memosEPSS 0.20%via NVD
memos vulnerabilities (CVEs) · VulnSea