VendorsTandoorrecipesany version
Vulnerabilities

Tandoor Recipes any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2025-23211
Tandoor Recipes - SSTI - Remote Code Execution
Published 2025-01-28 · Analyzed
9.9EPSS 0.036
CVE-2026-33152
Tandoor Recipes Vulnerable to Unrestricted Brute-Force via BasicAuthentication
Published 2026-03-26 · Analyzed
9.1EPSS 0.005
CVE-2025-23213
Tandoor Recipes - Stored XSS through Unrestricted File Upload
Published 2025-01-28 · Analyzed
8.7EPSS 0.004
CVE-2026-35488
Tandoor Recipes — CustomIsShared permits DELETE/PUT on RecipeBook by shared (read-only) users
Published 2026-04-07 · Analyzed
8.1EPSS 0.005
CVE-2026-33149
Tandoor Recipes Vulnerable to Host Header Injection
Published 2026-03-26 · Analyzed
8.1EPSS 0.004
CVE-2026-35045
Tandoor Recipes Affected by Private Recipe Exposure and Unauthorized Modification
Published 2026-04-06 · Analyzed
8.1EPSS 0.004
CVE-2025-23212
Tandoor Recipes - Local file disclosure - Users can read the content of any file on the server
Published 2025-01-28 · Analyzed
7.7EPSS 0.005
CVE-2026-33153
Tandoor Recipes's Unauthenticated Debug Parameter Leaks Full Raw SQL Queries Including Schema, Table Names, and Access Control Logic
Published 2026-03-26 · Analyzed
7.7EPSS 0.005
CVE-2026-25991
Tandoor Recipes affected by Blind SSRF with Internal Network Access via Recipe Import
Published 2026-02-13 · Analyzed
7.7EPSS 0.004
CVE-2026-35489
Tandoor Recipes — `amount`/`unit` bypass serializer in `food/{id}/shopping/`
Published 2026-04-07 · Analyzed
7.3EPSS 0.003
CVE-2022-23071
Recipes - SSRF on Import
Published 2022-06-19 · Modified
6.5EPSS 0.010
CVE-2026-33148
URL Parameter Injection in FDC Food Search API Causes Server Crash and Exposes Internal API Key
Published 2026-03-26 · Analyzed
6.5EPSS 0.005
CVE-2026-27460
Tandoor Recipes Affected by Denial of Service via Recipe Import
Published 2026-04-10 · Analyzed
6.5EPSS 0.004
CVE-2026-28503
Tandoor Recipes has Cross-Space IDOR in SyncViewSet.query_synced_folder: missing space scoping on get_object_or_404
Published 2026-03-26 · Analyzed
6.5EPSS 0.004
CVE-2026-35046
Tandoor has a Stored CSS Injection via <style> Tag in Recipe Instructions (API-Level)
Published 2026-04-06 · Analyzed
5.4EPSS 0.002
CVE-2026-29055
Tandoor Recipes: WebP and GIF Image Uploads Bypass EXIF/Metadata Stripping, Leaking GPS Coordinates and PII
Published 2026-03-26 · Analyzed
5.3EPSS 0.004
CVE-2026-25964
Tandoor Recipes Affected by Authenticated Local File Disclosure (LFD) via Recipe Import leads to Arbitrary File Read
Published 2026-02-13 · Analyzed
4.9EPSS 0.005
CVE-2022-23074
Recipes - Stored XSS in Name Parameter
Published 2022-06-21 · Modified
3.5EPSS 0.009
CVE-2022-23073
Recipes - Stored XSS in Clipboard
Published 2022-06-21 · Modified
3.5EPSS 0.009
CVE-2022-23072
Recipes - Stored XSS in Add to Cart
Published 2022-06-21 · Modified
3.5EPSS 0.009