An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1yZ2o1LWpqNXEtdjN2N84AAwZz

Moderate EPSS: 0.00271% (0.50336 Percentile) EPSS:

Memos Cross-site Scripting vulnerability

Affected Packages Affected Versions Fixed Versions
go:github.com/usememos/memos <= 0.8.3 No known fixed version
0 Dependent packages
0 Dependent repositories

Affected Version Ranges

All affected versions

0.0.1, 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.2.0, 0.2.1, 0.2.2, 0.3.0, 0.3.1, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.4.5, 0.5.0, 0.6.0, 0.6.1, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.8.0, 0.8.1, 0.8.2, 0.8.3

Memos, an open-source, self-hosted memo hub, is vulnerable to stored Cross-site Scripting (XSS) in versions 0.8.3 and prior. A patch is available and anticipated to be part of version 0.9.0.

References: