Mealie
14 known vulnerabilities
Top Products
A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1
A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticate
Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsani
A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allo
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an a
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an imag
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c
Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c
Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-mi
Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attack
Mealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to t
The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's respon
Frequently Asked Questions
How many CVEs affect Mealie?
Mealie has 14 CVE records in our database, including 2 critical and 1 high severity vulnerabilities.
What are the most severe Mealie vulnerabilities?
Mealie has 2 critical severity (CVSS 9.0+) and 1 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Mealie vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mealie products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mealie Vulnerabilities
CyberStrike scans your infrastructure for Mealie vulnerabilities and provides real-time remediation guidance.
Get Started