usememos
Security Risk Profile
36
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 76 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 19, 2022 to present
76
Total CVEs
55
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
7.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
36/100
low
Severity Distribution
Critical
11High
44Medium
19Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
XSS
25
2
CSRF
6
3
SSRF
4
4
Path Traversal
2
5
Infoleak
2
Most Affected Products
1. usememos memos76
2. go/github.com/usememos/memos22
3. npm/usememos5
4. Memos Memos4
Recent Vulnerabilities
See more →CVE-2026-30586
CVSS 6.1medium
6/2/2026🔧 No Patch
CVE-2026-6634
CVSS 2.1EPSS 0%low
usememos UpdateInstanceSetting App.tsx memos_access_token improper authorization
4/20/2026🔧 No Patch
CVE-2025-65798
CVSS 5.4medium
12/8/2025
CVE-2025-65796
CVSS 4.3medium
12/8/2025
CVE-2025-65797
CVSS 6.5medium
12/8/2025
CVE-2025-65795
CVSS 7.5high
12/8/2025
CVE-2025-65799
CVSS 4.3medium
12/8/2025
CVE-2024-21635
CVSS 7.5high
Memos Access Tokens Stay Valid after User Password Change
11/14/2025🔧 No Patch
CVE-2025-56761
CVSS 5.4medium
9/3/2025
CVE-2025-56760
CVSS 4.3medium
9/3/2025
Monitor usememos in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.