CVE-2025-56795
CRITICALMealie < 3.0.1 - XSS
Title source: ruleDescription
Mealie 3.0.1 and earlier is vulnerable to Stored Cross-Site Scripting (XSS) in the recipe creation functionality. Unsanitized user input in the "note" and "text" fields of the "/api/recipes/{recipe_name}" endpoint is rendered in the frontend without proper escaping leading to persistent XSS.
Exploits (1)
Scores
CVSS v3
9.0
EPSS
0.0005
EPSS Percentile
16.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-79
Status
published
Products (1)
mealie/mealie
< 3.0.1
Published
Sep 29, 2025
Tracked Since
Feb 18, 2026