mealie-recipes has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 4.3 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.3
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-93736Medium· 4.3Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path36CVE-2026-94028Medium· 4.3A weakness has been identified in mealie-recipes Mealie up to 3.25.124
mealie-recipes vulnerabilities
CVEs affecting mealie-recipes, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-94028Medium· 4.3A weakness has been identified in mealie-recipes Mealie up to 3.25.1
A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a…
▾ Sunlitmealie-recipes · MealieEPSS 0.45%via NVD
CVE-2026-93736Medium· 4.3PoCMealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path
Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attackers to read any user's recipe ratings and favorites by specifying arbitrary user IDs in the URL path. Attackers ca…
▾ Twilightmealie-recipes · mealieEPSS 0.39%via NVD