← Vulnerability feed

Vulnerability record · CVE-2025-56795 · published 29 September 2025

CVE-2025-56795: Mealie cross-site scripting vulnerability

Mealie · Mealie

Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.

9.0 CVSS 3.1 Critical EPSS 0.36% · top 72.3% CWE-79 · Cross-site scripting
9.0CVSS 3.1 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-56795 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34615Mealie weak password requirements vulnerabilityMealie 1.0.0beta3 employs weak password requirements which allows attackers to potentially gain unauthorized access to the application via brute-forc…EPSS 1.5%7.6CVE-2024-55073Mealie missing authorization vulnerabilityA Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profi…EPSS 0.30%6.5CVE-2024-31994Mealie uncontrolled resource consumption vulnerabilityMealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. Mealie…EPSS 0.28%6.5CVE-2024-31992Mealie uncontrolled resource consumption vulnerabilityMealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a requ…EPSS 0.72%6.5CVE-2022-34621Mealie insecure direct object reference vulnerabilityMealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attackers to modify user passwords …EPSS 1.0%6.1CVE-2025-70297Mealie cross-site scripting vulnerabilityA stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated …EPSS 0.19%5.9CVE-2022-34624Mealie insufficient session expiration vulnerabilityMealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-middle attack via a crafted GET…EPSS 0.61%5.4CVE-2025-70296Mealie command injection vulnerabilityA stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary H…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2025-56795), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.