« Volver al listado

Tandoor

Tandoor Recipes: vulnerabilidades y CVE

Tandoor Recipes tiene 23 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE23
Últimos 12 meses14
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-27460Media (6.5)0.44%—10 abr 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This…
CVE-2026-35489Alta (7.3)0.32%—7 abr 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from request.data and passes…
CVE-2026-35488Alta (8.1)0.50%—7 abr 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class,…
CVE-2026-35046Media (5.4)0.25%—6 abr 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authenticated users to inject arbitrary <style> tags into recipe step…
CVE-2026-35045Alta (8.1)0.38%—6 abr 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes allows any authenticated user within a…
CVE-2026-33153Alta (7.7)0.46%—26 mar 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpoint exposes a hidden `?debug=true` query parameter that returns the…
CVE-2026-33152Alta (7.5)0.53%—26 mar 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the…
CVE-2026-33149Alta (8.1)0.38%—26 mar 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which causes Django to accept any value in the…
CVE-2026-33148Media (6.5)0.48%—26 mar 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the FDC (USDA FoodData Central) search endpoint constructs an upstream API URL by directly…
CVE-2026-29055Media (5.3)0.36%—26 mar 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the image processing pipeline in Tandoor Recipes explicitly skips EXIF metadata stripping,…
CVE-2026-28503Media (5.5)0.40%—26 mar 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the `SyncViewSet.query_synced_folder()` action in `cookbook/views/api.py` (line 903)…
CVE-2026-25991Alta (7.7)0.44%—13 feb 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import…
CVE-2026-25964Media (4.9)0.55%—13 feb 2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of Tandoor Recipes allows authenticated…
CVE-2026-23838Alta (8.7)0.52%—19 ene 2026
Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using…
CVE-2025-57396Media (6.5)0.24%—19 sept 2025
Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User Profile API Endpoint containing two boolean values…
CVE-2025-23213Media (5.4)0.37%—28 ene 2025
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content…
CVE-2025-23212Media (6.5)0.52%—28 ene 2025
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This…
CVE-2025-23211Crítica (9.9)3.6%—28 ene 2025
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker…
CVE-2024-0403Media (6.5)0.43%—1 mar 2024
Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.
CVE-2022-23074Baja (3.5)0.85%—21 jun 2022
In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS…
CVE-2022-23073Baja (3.5)0.85%—21 jun 2022
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious…
CVE-2022-23072Baja (3.5)0.85%—21 jun 2022
In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript…
CVE-2022-23071Media (6.5)1.0%—19 jun 2022
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality. When an attacker enters the localhost URL, a low privileged attacker can access/read…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1210 Exploitation of Remote Services4
  3. T1005 Data from Local System2
  4. T1565.001 Stored Data Manipulation2
  5. T1059 Command and Scripting Interpreter1
  6. T1090 Proxy1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.