Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.45% | — | Mealie-recipes MealieAI | 20/9/2026 | 21/9/2026 | A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery. The… | |
| Aplazada | Media (6.4) | 0.33% | — | Delicious RecipesAI | 16/7/2026 | 16/7/2026 | The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value… | |
| Aplazada | Alta (8.5) | 0.36% | — | ZIP RecipesAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions. | |
| Analizada | Media (6.5) | 0.44% | — | Tandoor Recipes | 10/4/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated user to crash the server or make a significantly degrade its… | |
| Aplazada | Media (5.3) | 0.31% | — | Wpdelicious Delicious RecipesAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5. | |
| Analizada | Alta (7.3) | 0.32% | — | Tandoor Recipes | 7/4/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from request.data and passes them without validation to ShoppingListEntry.objects.create(). Invalid amount values (non-numeric… | |
| Analizada | Alta (8.1) | 0.50% | — | Tandoor Recipes | 7/4/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class, but CustomIsShared.has_object_permission() returns True for all HTTP methods — including DELETE, PUT,… | |
| Analizada | Media (5.4) | 0.25% | — | Tandoor Recipes | 6/4/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authenticated users to inject arbitrary <style> tags into recipe step instructions. The bleach.clean() sanitizer explicitly whitelists the <style> tag, causing the backend to… | |
| Analizada | Alta (8.1) | 0.38% | — | Tandoor Recipes | 6/4/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes allows any authenticated user within a Space to modify any recipe in that Space, including recipes marked as private by other users. This… | |
| Analizada | Alta (7.7) | 0.46% | — | Tandoor Recipes | 26/3/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpoint exposes a hidden `?debug=true` query parameter that returns the complete raw SQL query being executed, including all table names, column names, JOIN relationships,… | |
| Analizada | Alta (7.5) | 0.53% | — | Tandoor Recipes | 26/3/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the default authentication backends. The AllAuth rate limiting configuration (ACCOUNT_RATE_LIMITS: login:… | |
| Analizada | Alta (8.1) | 0.38% | — | Tandoor Recipes | 26/3/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which causes Django to accept any value in the HTTP Host header without validation. The application uses request.build_absolute_uri() to generate… | |
| Analizada | Media (6.5) | 0.48% | — | Tandoor Recipes | 26/3/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the FDC (USDA FoodData Central) search endpoint constructs an upstream API URL by directly interpolating the user-supplied `query` parameter into the URL string without URL-encoding. An… | |
| Analizada | Media (5.3) | 0.36% | — | Tandoor Recipes | 26/3/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the image processing pipeline in Tandoor Recipes explicitly skips EXIF metadata stripping, image rescaling, and size validation for WebP and GIF image formats. A developer TODO comment in… | |
| Analizada | Media (5.5) | 0.40% | — | Tandoor Recipes | 26/3/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the `SyncViewSet.query_synced_folder()` action in `cookbook/views/api.py` (line 903) fetches a Sync object using `get_object_or_404(Sync, pk=pk)` without including `space=request.space` in… | |
| Analizada | Alta (7.7) | 0.44% | — | Tandoor Recipes | 13/2/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import feature of Tandoor Recipes. The application fails to validate the destination URL after following HTTP… | |
| Analizada | Media (4.9) | 0.55% | — | Tandoor Recipes | 13/2/2026 | 17/6/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of Tandoor Recipes allows authenticated users with import permissions to read arbitrary files on the server. This vulnerability stems from a… | |
| Aplazada | Alta (8.7) | 0.52% | — | Tandoor RecipesAINixosAI | 19/1/2026 | 17/6/2026 | Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `MEDIA_ROOT`, the full database file may be externally accessible, potentially on… | |
| Aplazada | Media (4.3) | 0.23% | — | Strategy11 Tasty Recipes LiteAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team Tasty Recipes Lite tasty-recipes-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tasty Recipes Lite: from n/a through <= 1.1.5. | |
| Aplazada | Media (4.3) | 0.18% | — | Strategy11 Tasty Recipes LiteAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team Tasty Recipes Lite tasty-recipes-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tasty Recipes Lite: from n/a through <= 1.1.5. | |
| Aplazada | Media (6.5) | 0.27% | — | Wpdelicious Delicious RecipesAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.1. | |
| Analizada | Media (6.5) | 0.24% | — | Tandoor Recipes | 19/9/2025 | 17/6/2026 | Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User Profile API Endpoint containing two boolean values indicating whether a user is staff or administrative. Consequently, any user can escalate their privileges to… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpdelicious Delicious RecipesAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows Stored XSS.This issue affects WP Delicious: from n/a through <= 1.8.7. | |
| Aplazada | Media (6.5) | 0.17% | — | Wpdelicious Delicious-recipesAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP Delicious delicious-recipes allows DOM-Based XSS.This issue affects WP Delicious: from n/a through <= 1.8.4. | |
| Aplazada | Media (5.9) | 0.26% | — | Felix Martinez Recipes Manager - WPHAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Félix Martínez Recipes manager - WPH allows Stored XSS. This issue affects Recipes manager - WPH: from n/a through 1.0.4. |