CVE-2026-30586: XSS
Published Jun 2, 2026
·Updated
Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZESCHEMA, Memo Rendering Component, and Public/Private Memo View pages
Affected Software
1 affected component
usememos memos=0.26.0
Event History
Jun 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-30586?
The severity of CVE-2026-30586 is rated as medium with a score of 6.1 according to CVSS 3.1.
2
What type of vulnerability is CVE-2026-30586?
CVE-2026-30586 is a Cross Site Scripting (XSS) vulnerability affecting usememos Memos v.0.26.0.
3
How does CVE-2026-30586 affect users?
CVE-2026-30586 allows a remote attacker to obtain sensitive information by exploiting the vulnerability in the Memo Rendering Component and views.
4
How can I mitigate CVE-2026-30586?
To mitigate CVE-2026-30586, update to the latest version of usememos that addresses this vulnerability.
5
What components are affected by CVE-2026-30586?
CVE-2026-30586 affects the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View pages.