VulnSea

usememos has 6 CVEs on record between 2025 and 2026. The busiest recent month was December 2025 with 5. The median CVSS is 5.8 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-284 (4). Most affected products: memos (5), github.com/usememos/memos (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.8
Publish → KEV
Last 90 days
0 prev 1

Weakness classes

Products

  • memos 5
  • github.com/usememos/memos 1
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

usememos vulnerabilities

CVEs affecting usememos, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-6634Medium· 6.3
5mo ago

Memos has an Incorrect Privilege Assignment issue

Memos has an Incorrect Privilege Assignment issue

Sunlitusememos · github.com/usememos/memosEPSS 0.25%via OSV
CVE-2025-65799Medium· 4.3
9mo ago

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal.

Sunlitusememos · memosEPSS 0.21%via NVD
CVE-2025-65797Medium· 6.5
9mo ago

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…

Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete registered identity providers, leading to an account takeover or Denial of Ser…

Sunlitusememos · memosEPSS 0.28%via NVD
CVE-2025-65795High· 7.5
9mo ago

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a crafted request.

Twilightusememos · memosEPSS 0.26%via NVD
CVE-2025-65798Medium· 5.4
9mo ago

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by other users.

Sunlitusememos · memosEPSS 0.18%via NVD
CVE-2025-65796Medium· 4.3
9mo ago

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily delete reactions made to other users' Memos.

Sunlitusememos · memosEPSS 0.20%via NVD
usememos vulnerabilities (CVEs) · VulnSea