Mealie Project develops a recipe management and meal-planning application with a web-based interface, where the durable vulnerability signal centers on input-handling and file-upload issues including cross-site scripting, code injection, and unrestricted file uploads. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mealie Project over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34615CRITICAL Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. | Aug 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-34613CRITICAL Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file. | Aug 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-56795CRITICAL Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/ap | Sep 29, 2025 | 9.0 | 29 | NO | NO |
CVE-2022-34624MEDIUM Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET request. | Aug 19, 2022 | 5.9 | 23 | NO | NO |
CVE-2022-34625HIGH Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template. | Aug 2, 2022 | 7.2 | 23 | NO | NO |
CVE-2024-55073HIGH A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves | Mar 27, 2025 | 7.6 | 22 | NO | NO |
CVE-2022-34621MEDIUM Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords and other attributes via modifi | Aug 19, 2022 | 6.5 | 22 | NO | NO |
CVE-2025-70297MEDIUM A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary web s | Feb 11, 2026 | 6.1 | 21 | NO | NO |
CVE-2024-31994MEDIUM Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. Mealie will attempt to retrieve this | Apr 19, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-31992MEDIUM Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to a remote server, however | Apr 19, 2024 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mealie Project.
Media articles that mention a CVE ID that affects a product developed by Mealie Project — matched by CVE ID, not by vendor name.