Bounties
Partners
Community
Info
usememos / memos
Project repository
An open source, lightweight note-taking service. Easily capture and share your great thoughts.
Submit a report
FIRST INTERACTION
WITHIN
2 DAYS
REVIEW
WITHIN
14 DAYS
FIX
WITHIN
13 DAYS
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Sep 26th 2023
qqliunian2001
•
pending
Cross-Site Request Forgery Vulnerability in Logout Functionality
Sep 25th 2023
qqliunian2001
•
pending
Unverified password change : old password can be used as new password
Sep 24th 2023
th3l0newolf
•
pending
weak password policy on user creation
Sep 24th 2023
th3l0newolf
•
pending
Insecure Storage of Sensitive Information in Memos
Sep 24th 2023
muhamedfarish
•
pending
Stored XSS in resource upload
Sep 21st 2023
rootaux
•
pending
Invalid markdown can result in DoS for RSS feeds
Sep 21st 2023
rootaux
•
pending
CSRF - User performed an unexpected sign out
Sep 19th 2023
hainguyen0207
•
pending
IDOR - User can edit rowStatus:(ARCHIVED, NORMAL)
Sep 19th 2023
hainguyen0207
•
pending
Open Redirect at File Upload Vulnerabilities
Sep 18th 2023
hainguyen0207
•
pending
XSS/CSRF in GetImage Endpoint
Sep 18th 2023
victorsch
•
High
High
•
CVE-2023-5036
CVE-2023-5036
Unverified Password Change in Settings Page
Sep 15th 2023
victorsch
•
pending
Modify avatar to svg xss image
Sep 12th 2023
8910jq
•
pending
Picture EXIF GPS information not stripped
Sep 12th 2023
8910jq
•
pending
PDF XSS
Sep 12th 2023
8910jq
•
pending
List users on system for unauthen user and no ratelimit
May 27th 2024
meme-dm
•
self closed
Local File Inclusion (LFI)
Sep 1st 2023
mnqazi
•
High
High
•
CVE-2023-4698
CVE-2023-4698
Account TakeOver Due to Improper Handling of JWT Tokens
Sep 1st 2023
mnqazi
•
Critical
Critical
•
CVE-2023-4696
CVE-2023-4696
archied users can still read and post thoughts.
Apr 12th 2023
lujiefsi
•
pending
Vulnerable to clickjacking
Nov 16th 2023
liteshghute
•
self closed
No limit in the length of openId token results in DOS attack /memory corruption
Mar 16th 2023
karthik983
•
pending
IDOR at change password leads to Account Takeover of any user
Mar 15th 2023
karthik983
•
not applicable
User Enumeration via response timing
Mar 15th 2023
karthik983
•
informative
Medium
IDOR to access stats of any user
Mar 13th 2023
karthik983
•
pending
Pre-auth semi-blind SSRF via /httpmeta endpoint
Feb 27th 2023
yuriisanin
•
pending
Admin can change other user's openId value and can change to desired value
Feb 27th 2023
5h4s1
•
not applicable
ADMIN may activate his account storage resulting in the Deactivate ADMIN
Feb 25th 2023
5h4s1
•
pending
No Protection against Bruteforce attacks on Login page
Feb 25th 2023
5h4s1
•
pending
Enumeration Attack at the login function
Feb 26th 2023
5h4s1
•
self closed
A ssrf in public endpoint
Feb 19th 2023
yoshino-s
•
pending
Deleted user is able to see his account details
Feb 17th 2023
earth2sky
•
pending
Application allows to create account with blank user name and password
Feb 17th 2023
earth2sky
•
pending
Cookie Session Not Expiring in usememos/memos
Jan 29th 2023
syq1207
•
pending
Cross-Site Request Forgery (CSRF) in Add Users bypass CSRF token in usememos/mem...
Jan 29th 2023
syq1207
•
pending
IDOR allows to archive any Account including the ADMIN Account and lockout the A...
Jan 25th 2023
ahmedvienna
•
pending
IDOR allowing ADMIN to manipulate all the Users Information including E-Mail and...
Jan 25th 2023
ahmedvienna
•
pending
White spaces as username leads to permanent Account Lockout and no assignment of...
Jan 25th 2023
ahmedvienna
•
pending
Full Account Take over
Feb 18th 2023
0ozero0
•
informative
High
DDOS Attack through External Ressources
Jan 24th 2023
ahmedvienna
•
pending
IDOR (Insecure Direct Object Reference) allows an attacker to gain access to all...
Jan 24th 2023
ahmedvienna
•
pending
Admin Account Takeover allows controlling and the new Setup of the whole System
Jan 24th 2023
ahmedvienna
•
pending
Unauthorized access to files stored on Memos.
Feb 17th 2023
kkasdk
•
informative
Medium
Validation bypass leads to Denial of service (DDos)
Jan 18th 2023
geethu-sudosu
•
pending
DDOS attack by uploading a few hundred large files
Jan 17th 2023
ahmed8magdy
•
pending
IDOR to read the file of another user
Jan 16th 2023
zoro2000
•
pending
Username enumeration via login api feature
Jan 16th 2023
mike993
•
pending
IDOR in /api/memo?creatorId=:userId&visibility=:visibility endpoint allows to vi...
Jan 14th 2023
panya
•
pending
memos_session Cookie Set Without 'Secure" Flag
Jan 12th 2023
0xsu3ks
•
pending
Adding Shortcuts inside Admin Panel without any privilege
Jan 10th 2023
7h3h4ckv157
•
pending
xss via The href attribute of the a tag
Jan 10th 2023
christynorl
•
pending
Stored xss using Additional script
Jan 9th 2023
xo19do
•
pending
IDOR leads to updation of other users information
Jan 9th 2023
nithissh200
•
pending
User Enumeration through the Login Function [/api/auth/signin]
Jan 9th 2023
itsfading
•
pending
Privilege escalation API list user
Jan 9th 2023
duongli99
•
pending
Click Jacking
Jan 8th 2023
imsushantkamble
•
pending
Access Control Issue due to vulnerable cache integration
Jan 8th 2023
xanhacks
•
pending
user name enumeration
Jan 8th 2023
adwaithcp
•
pending
Preview resource does not authenticate user
Jan 8th 2023
duongli99
•
pending
Privilege vulnerability at API Delete Tags
Jan 8th 2023
duongli99
•
pending
IDOR to pin/unpin memo
Jan 8th 2023
duongli99
•
pending
a non user can enumrate all users details wit(IDOR)
Jan 7th 2023
leminv
•
pending
Broken access control allow to Access uploaded files of any user
Jan 5th 2023
gaurav-g2
•
pending
Missing Function Level Access Control
Jan 5th 2023
domiee13
•
pending
Stored XSS by link markdown
Jan 7th 2023
j0ok34n
•
Critical
Critical
•
CVE-2023-0106
CVE-2023-0106
Stored XSS via markdown link
Jan 7th 2023
domiee13
•
Medium
Medium
•
CVE-2023-0107
CVE-2023-0107
XSS via upload pdf file
Jan 7th 2023
christynorl
•
High
High
•
CVE-2023-0108
CVE-2023-0108
Stored XSS using two files
Jan 7th 2023
xmosb7
•
Critical
Critical
•
CVE-2023-0109
CVE-2023-0109
improper access control
Jan 1st 2023
toradagamil
•
pending
Stored XSS
Dec 30th 2022
mohamedabdelhady933
•
duplicate
High
Bypass Stored XSS while creating a new post
Dec 31st 2022
xo19do
•
High
High
•
CVE-2022-4865
CVE-2022-4865
Admin is able to ARCHIVE OWN Account leads to Deactivate ADMIN Account
Dec 30th 2022
xo19do
•
High
High
•
CVE-2022-4863
CVE-2022-4863
privilege escalation : Low access user can view Admin PRIVATE POST by using PI...
Sep 1st 2023
xo19do
•
High
High
•
CVE-2023-4697
CVE-2023-4697
Bypassing filters to trigger XSS while creating memos
Dec 31st 2022
nehalr777
•
Critical
Critical
•
CVE-2022-4866
CVE-2022-4866
CSRF allows attacker trigger admin add HOST user lead to takeover memos applicat...
Dec 29th 2022
shino-337
•
Medium
Medium
•
CVE-2022-4844
CVE-2022-4844
Able to assign ADMIN role to new User
Dec 30th 2022
trumthiphi
•
informative
High
Unpinning, Pinning, & Editing Other Users Shortcuts & Editing Resource Filenames...
Dec 29th 2022
1d8
•
duplicate
High
IDOR To Access Other Users' Resources
Dec 29th 2022
1d8
•
pending
Add any thoughts via CSRF
Dec 29th 2022
samirwaleed
•
Medium
Medium
•
CVE-2022-4845
CVE-2022-4845
Cross-Site Request Forgery (CSRF) in Add Users
Dec 29th 2022
xo19do
•
Medium
Medium
•
CVE-2022-4846
CVE-2022-4846
CSRF to change user language preferences
Dec 29th 2022
nehalr777
•
High
High
•
CVE-2022-4847
CVE-2022-4847
CSRF to add shortcuts to victim account
Dec 29th 2022
nehalr777
•
High
High
•
CVE-2022-4848
CVE-2022-4848
IDOR to delete user resources
Dec 28th 2022
nehalr777
•
High
High
•
CVE-2022-4812
CVE-2022-4812
IDOR to delete memo from archives
Dec 28th 2022
nehalr777
•
High
High
•
CVE-2022-4813
CVE-2022-4813
IDOR to archive victims memo
Dec 28th 2022
nehalr777
•
High
High
•
CVE-2022-4814
CVE-2022-4814
Stored XSS while creating a new post
Dec 29th 2022
xo19do
•
High
High
•
CVE-2022-4839
CVE-2022-4839
Able to assign HOST role to new User
Dec 28th 2022
xo19do
•
Medium
Medium
•
CVE-2022-4808
CVE-2022-4808
Mass Assignment Vulnerability in Memo Creation Endpoint allows creating new memo...
Dec 29th 2022
alanbriangh
•
duplicate
High
Cross Site Request Forgery in Create a Memo Functionality (POST /api/memo)
Dec 29th 2022
alanbriangh
•
Medium
Medium
•
CVE-2022-4850
CVE-2022-4850
Stored XSS with CSP bypass through JS file upload
Jan 7th 2023
leorac
•
Medium
Medium
•
CVE-2023-0111
CVE-2023-0111
An attacker can be post message in other memos page
Dec 29th 2022
quangdaik2362001
•
Critical
Critical
•
CVE-2022-4851
CVE-2022-4851
IDOR allows to see, update and delete other users shortcuts
Dec 28th 2022
leorac
•
Critical
Critical
•
CVE-2022-4802
CVE-2022-4802
IDOR allows to see and delete other users resources
Dec 26th 2022
leorac
•
self closed
Get all file in resource of any user and Delete any file of any user via IDOR
Dec 28th 2022
trumthiphi
•
High
High
•
CVE-2022-4803
CVE-2022-4803
Unauthorized Attacker Can Change Visibility Status of Victim's Memos
Dec 28th 2022
1d8
•
High
High
•
CVE-2022-4804
CVE-2022-4804
Delete all note of all user in application
Dec 28th 2022
trumthiphi
•
High
High
•
CVE-2022-4796
CVE-2022-4796
An user can delete other user's post
Dec 28th 2022
quangdaik2362001
•
Critical
Critical
•
CVE-2022-4797
CVE-2022-4797
Get all information any user via IDOR without login
Dec 29th 2022
trumthiphi
•
self closed
Failure to Invalidate Session on Logout
Dec 25th 2022
drxadz
•
pending
Privilege Escalation
Dec 25th 2022
mohamedabdelhady933
•
pending
takeover all users accounts
Dec 30th 2022
wickrine
•
informative
High
User's private Information Disclosure At API Endpoint
Dec 30th 2022
wickrine
•
informative
High
Admin account takeover
Dec 30th 2022
xtaraim
•
informative
High
Reset API any user via IDOR
Dec 28th 2022
samirwaleed
•
High
High
•
CVE-2022-4798
CVE-2022-4798
Delete any post for all users via IDOR
Dec 28th 2022
samirwaleed
•
High
High
•
CVE-2022-4799
CVE-2022-4799
Stored XSS in resource file uploading
Jan 7th 2023
benasin
•
High
High
•
CVE-2023-0112
CVE-2023-0112
Archive any post (public / private) using IDOR
Dec 28th 2022
samsamurai
•
High
High
•
CVE-2022-4801
CVE-2022-4801
IDOR results in deletion of others public & private memos
Dec 28th 2022
argonx21
•
High
High
•
CVE-2022-4806
CVE-2022-4806
Users can edit and delete all other user shortcuts
Dec 28th 2022
juylang
•
High
High
•
CVE-2022-4807
CVE-2022-4807
CSRF allows attacker to add malicious tags to vitim account
Dec 28th 2022
nehalr777
•
High
High
•
CVE-2022-4800
CVE-2022-4800
CSRF allows attacker to post on behalf of victim
Dec 29th 2022
nehalr777
•
High
High
•
CVE-2022-4849
CVE-2022-4849
CSP passby via js file
Jan 7th 2023
christynorl
•
High
High
•
CVE-2023-0110
CVE-2023-0110
Stored XSS while adding a memo
Dec 29th 2022
nehalr777
•
High
High
•
CVE-2022-4841
CVE-2022-4841
Stored XSS in memos while creating
Dec 29th 2022
mohamedabdelhady933
•
High
High
•
CVE-2022-4840
CVE-2022-4840
Archive any private memos + Delete any Shortcut + Edit any Shortcut from other u...
Dec 28th 2022
kevinkien
•
High
High
•
CVE-2022-4805
CVE-2022-4805
View any content private memos from other users
Dec 28th 2022
kevinkien
•
Medium
Medium
•
CVE-2022-4810
CVE-2022-4810
Access all Private Memos by unauthorized user
Dec 28th 2022
mohamedabdelhady933
•
High
High
•
CVE-2022-4811
CVE-2022-4811
Denial of Service
Dec 27th 2022
mohamedabdelhady933
•
High
High
•
CVE-2022-4767
CVE-2022-4767
Full account takeover
Dec 28th 2022
mohamedabdelhady933
•
High
High
•
CVE-2022-4809
CVE-2022-4809
Email exposure of users to an authorized user
Dec 25th 2022
ayoub0x1
•
High
High
•
CVE-2022-4734
CVE-2022-4734
Reset API any user via IDOR
Dec 23rd 2022
samirwaleed
•
High
High
•
CVE-2022-4686
CVE-2022-4686
Critical Account Takeover and Privilege Escalation
Dec 23rd 2022
michaellok001
•
High
High
•
CVE-2022-4685
CVE-2022-4685
Stored XSS in Search
Dec 23rd 2022
uonghoangminhchau
•
Medium
Medium
•
CVE-2022-4694
CVE-2022-4694
Privilege vulnerability at API Change Password
Dec 23rd 2022
uonghoangminhchau
•
High
High
•
CVE-2022-4687
CVE-2022-4687
Cookie without Secure attribute
Dec 23rd 2022
uonghoangminhchau
•
Medium
Medium
•
CVE-2022-4683
CVE-2022-4683
A user can update information / password from other users
Dec 23rd 2022
acciobugs
•
High
High
•
CVE-2022-4688
CVE-2022-4688
A user can edit private memos from other users
Dec 23rd 2022
acciobugs
•
High
High
•
CVE-2022-4684
CVE-2022-4684
XSS by uploading svg files
Dec 23rd 2022
christynorl
•
High
High
•
CVE-2022-4692
CVE-2022-4692
Cross-site scripting - Stored via upload `.svg` file in
Dec 23rd 2022
juylang
•
High
High
•
CVE-2022-4691
CVE-2022-4691
Stored XSS via SVG File
Dec 23rd 2022
mike993
•
High
High
•
CVE-2022-4690
CVE-2022-4690
Stored XSS while creating a new post
Dec 23rd 2022
mohamedabdelhady933
•
High
High
•
CVE-2022-4695
CVE-2022-4695
Account takeover via changing password
Dec 23rd 2022
mohamedabdelhady933
•
High
High
•
CVE-2022-4689
CVE-2022-4689
Cross-site scripting
Dec 19th 2022
lujiefsi
•
High
High
•
CVE-2022-4609
CVE-2022-4609
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0