Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | SEO Nutrition AND Print FOR Recipes BY EdamamAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Edamam SEO, Nutrition and Print for Recipes by Edamam seo-nutrition-and-print-for-recipes-by-edamam allows Stored XSS.This issue affects SEO, Nutrition and Print for Recipes by Edamam: from n/a through <= 3.3. | |
| Aplazada | Media (6.5) | 0.36% | — | Boospotllc BOO RecipesAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BooSpot Boo Recipes boo-recipes allows Stored XSS.This issue affects Boo Recipes: from n/a through <= 2.4.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Yummly Rich RecipesAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Yummly Yummly Rich Recipes yummly-rich-recipes allows Cross Site Request Forgery.This issue affects Yummly Rich Recipes: from n/a through <= 4.2. | |
| Analizada | Media (5.4) | 0.37% | — | Tandoor Recipes | 28/1/2025 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28. | |
| Analizada | Media (6.5) | 0.52% | — | Tandoor Recipes | 28/1/2025 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28. | |
| Analizada | Crítica (9.9) | 3.6% | 💥 Exploit | Tandoor Recipes | 28/1/2025 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24. | |
| Modificada | Media (6.5) | 0.43% | — | Tandoor Recipes | 1/3/2024 | 17/6/2026 | Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF. | |
| Modificada | Alta (8.1) | 0.48% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.1.0. | |
| Modificada | Media (6.1) | 0.38% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions. | |
| Modificada | Baja (3.5) | 0.85% | — | Tandoor Recipes | 21/6/2022 | 17/6/2026 | In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privileged attacker will have the victim's API key and can lead to admin's… | |
| Modificada | Baja (3.5) | 0.85% | — | Tandoor Recipes | 21/6/2022 | 17/6/2026 | In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the clipboard icon, an XSS payload will trigger. A… | |
| Modificada | Baja (3.5) | 0.85% | — | Tandoor Recipes | 21/6/2022 | 17/6/2026 | In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter and clicks on the Add to Shopping Cart icon, an XSS payload will… | |
| Modificada | Media (6.5) | 1.0% | — | Tandoor Recipes | 19/6/2022 | 17/6/2026 | In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read the internal file system to access sensitive information. | |
| Modificada | Media (5.9) | 0.49% | — | Zipongo Inc. Healthy Recipes AND Grocery Deals | 15/5/2017 | 17/6/2026 | The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.1) | 2.2% | — | Recipes-writer Project Recipes-writer | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin recipes-writer v1.0.4 | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Phpmyrecipes Project Phpmyrecipes | 2/1/2015 | 17/6/2026 | SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Phpmyrecipes Project Phpmyrecipes | 8/12/2014 | 17/6/2026 | SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the words_exact parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Androidebookapp Healthy Lunch Diet Recipes | 19/10/2014 | 17/6/2026 | The Healthy Lunch Diet Recipes (aka com.best.lunchdietrecipes) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Mbtcreations Detox Juicing Diet Recipes | 19/10/2014 | 17/6/2026 | The Detox Juicing Diet Recipes (aka com.wDetoxJuicingDietRecipes) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Scriptsfeed Recipes Listing Portal | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Scriptsfeed Recipes Listing Portal | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Recipescript Recipe Script | 18/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomla COM RecipesMambo COM Recipes | 31/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | |
| Analizada | Alta (7.5) | 1.4% | 💥 Exploit | Softbizscripts Recipes Portal Script | 14/10/2007 | 16/6/2026 | SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter. |