📦 Mealie

by Mealie

🔍 What is Mealie?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-56795

CRITICAL CVSS 9.0 Sep 29, 2025

CVE-2025-56795 is a stored cross-site scripting vulnerability in Mealie recipe management software. Attackers can inject malicious scripts into recipe notes and text fields that execute when other use...

CVE-2024-55073

HIGH CVSS 7.6 Mar 27, 2025

A Broken Object Level Authorization vulnerability in Mealie v2.2.0 allows authenticated users to modify their own profile to escalate privileges or change household assignments. This affects all Meali...

CVE-2025-70296

MEDIUM CVSS 5.4 Feb 11, 2026

A stored HTML injection vulnerability in Mealie 3.3.1 allows authenticated users to inject arbitrary HTML into recipe notes, which can lead to user interface redressing attacks. This affects all users...

CVE-2025-70297

MEDIUM CVSS 6.1 Feb 11, 2026

A stored cross-site scripting (XSS) vulnerability in Mealie 3.3.1 allows authenticated users to upload malicious SVG files that execute arbitrary JavaScript when viewed by other users. This affects al...