Mealie Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-31991

    Mealie vulnerable to a GET-based SSRF in recipe importer (GHSL-2023-225)

    Last Modified: Mar 07, 2025
    Published: Apr 19, 2024

    CVE-2022-34619

    A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Shopping Lists item names text field.

    Last Modified: Nov 21, 2024
    Published: Aug 02, 2022

    CVE-2022-34625

    Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template.

    Last Modified: Nov 21, 2024
    Published: Aug 02, 2022

    CVE-2022-34613

    Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.

    Last Modified: Nov 21, 2024
    Published: Aug 02, 2022

    CVE-2022-34618

    A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.

    Last Modified: Nov 21, 2024
    Published: Aug 02, 2022
    Items Per Page