usememos has 6 CVEs on record between 2025 and 2026. The busiest recent month was December 2025 with 5. The median CVSS is 5.8 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-284 (4). Most affected products: memos (5), github.com/usememos/memos (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 1
Worst active — by depth score
CVE-2025-65795High· 7.5Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.41CVE-2025-65797Medium· 6.5Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…36CVE-2026-6634Medium· 6.3Memos has an Incorrect Privilege Assignment issue35CVE-2025-65798Medium· 5.4Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.30CVE-2025-65799Medium· 4.3A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.24
usememos vulnerabilities
CVEs affecting usememos, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-6634Medium· 6.3Memos has an Incorrect Privilege Assignment issue
Memos has an Incorrect Privilege Assignment issue
CVE-2025-65799Medium· 4.3A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.
A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.
CVE-2025-65797Medium· 6.5Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…
CVE-2025-65795High· 7.5Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.
CVE-2025-65798Medium· 5.4Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.
CVE-2025-65796Medium· 4.3Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.