Boxystudio
Boxystudio Cooked: vulnerabilities and CVEs
Boxystudio Cooked has 14 published vulnerabilities, 3 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs14
Last 12 months3
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73999 | Medium (5.4) | 0.29% | — | Sep 17, 2026 | Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. |
| CVE-2025-62989 | Medium (5.9) | 0.17% | — | Dec 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gora Tech Cooked cooked allows Stored XSS.This issue affects Cooked: from n/a through <= 1.11.3. |
| CVE-2025-68586 | Medium (5.3) | 0.25% | — | Dec 24, 2025 | Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cooked: from n/a through <= 1.11.3. |
| CVE-2024-49290 | High (8.8) | 0.22% | — | Oct 20, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Gora Tech LLC Cooked Pro allows Cross Site Request Forgery.This issue affects Cooked Pro: from n/a before 1.8.0. |
| CVE-2024-41816 | Medium (5.4) | 0.38% | — | Aug 5, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to… |
| CVE-2024-39682 | Medium (5.4) | 0.36% | — | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This… |
| CVE-2024-39681 | High (8.8) | 0.33% | — | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the… |
| CVE-2024-39680 | High (8.8) | 0.33% | — | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the… |
| CVE-2024-39679 | High (8.8) | 0.34% | — | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the… |
| CVE-2024-39678 | High (8.8) | 0.34% | — | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action… |
| CVE-2024-37308 | Medium (5.4) | 0.43% | — | Jun 13, 2024 | The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input… |
| CVE-2023-44477 | Medium (5.4) | 0.33% | — | Oct 2, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions. |
| CVE-2022-3900 | Critical (9.8) | 19% | — | Dec 12, 2022 | The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a… |
| CVE-2021-24233 | Medium (6.1) | 1.7% | — | Apr 22, 2021 | The Cooked Pro WordPress plugin before 1.7.5.6 was affected by unauthenticated reflected Cross-Site Scripting issues, due to improper sanitisation of user input while being output back in pages as an arbitrary attribute. |