Product
mealie
18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-70297
CVE-2025-70296
CVE-2025-56795
CVE-2024-55070
CVE-2024-55073
CVE-2024-55072
CVE-2024-31994
CVE-2024-31993
CVE-2024-31992
CVE-2024-31991
CVE-2022-34624
CVE-2022-34621
CVE-2022-34615
CVE-2022-34619
CVE-2022-34625
CVE-2022-34618
CVE-2022-34613
CVE-2022-32425
>= 3.3.1 and < 3.6.0
A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows re
>= 3.3.1 and < 3.8.0
A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to
<= 3.0.1
Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user
all versions
A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allows group m
all versions
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to e
all versions
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to e
< 1.4.0
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily
< 1.4.0
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an image based on
< 1.4.0
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled
< 1.4.0
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled
all versions
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attac
all versions
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to mod
all versions
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the applica
all versions
A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a
all versions
Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbit
all versions
A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML v
all versions
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted f
all versions
The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's response time.