Vulnerabilities

Summary — last 7 days

New vulnerabilities2,577▼ 295 vs. last week
Critical / high1,354▲ 102 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

129 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.5)0.18%—Bootstrapped WP Recipe MakerAI9/23/20269/23/2026
The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes.
DeferredHigh (8.2)0.24%—Bootstrapped WP Recipe MakerAI9/23/20269/23/2026
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from…
DeferredMedium (4.3)0.18%—Bootstrapped WP Recipe MakerAI9/23/20269/23/2026
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists.
DeferredMedium (4.3)0.18%—Bootstrapped WP Recipe MakerAI9/23/20269/23/2026
The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes.
DeferredLow (2.1)0.45%—Mealie-recipes MealieAI9/20/20269/21/2026
A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery. The…
DeferredCritical (9.1)0.68%—Bootstrapped WP Recipe MakerAI9/19/20269/21/2026
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the…
DeferredMedium (5.4)0.24%—Bootstrapped WP Recipe MakerAI9/18/20269/18/2026
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
DeferredMedium (4.3)0.37%—Bootstrapped WP Recipe MakerAI9/9/20269/9/2026
The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to…
DeferredMedium (6.4)0.26%—Bootstrapped WP Recipe MakerAI9/1/20269/1/2026
The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and including, 10.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
DeferredHigh (7.1)0.25%—Recipe Card Blocks FOR Gutenberg AND ElementorAI8/18/20268/20/2026
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
DeferredMedium (6.4)0.33%—Delicious RecipesAI7/16/20267/16/2026
The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value…
DeferredHigh (8.5)0.36%—ZIP RecipesAI6/26/20266/26/2026
Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.
AnalyzedHigh (8.8)0.43%—Joomboost Joomrecipe6/19/20268/19/2026
Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL payloads in the category path segment to…
AnalyzedHigh (8.8)0.46%—Joomboost Joomla Joomrecipe6/19/20268/19/2026
Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques.
DeferredMedium (6.4)0.35%—Recipe Card Blocks LiteAI6/8/20267/23/2026
The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into…
AnalyzedMedium (6.5)0.44%—Tandoor Recipes4/10/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated user to crash the server or make a significantly degrade its…
DeferredMedium (5.3)0.31%—Wpdelicious Delicious RecipesAI4/8/20267/24/2026
Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5.
AnalyzedHigh (7.3)0.32%—Tandoor Recipes4/7/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from request.data and passes them without validation to ShoppingListEntry.objects.create(). Invalid amount values (non-numeric…
AnalyzedHigh (8.1)0.50%—Tandoor Recipes4/7/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class, but CustomIsShared.has_object_permission() returns True for all HTTP methods — including DELETE, PUT,…
AnalyzedMedium (5.4)0.25%—Tandoor Recipes4/6/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authenticated users to inject arbitrary <style> tags into recipe step instructions. The bleach.clean() sanitizer explicitly whitelists the <style> tag, causing the backend to…
AnalyzedHigh (8.1)0.38%—Tandoor Recipes4/6/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes allows any authenticated user within a Space to modify any recipe in that Space, including recipes marked as private by other users. This…
AnalyzedHigh (7.7)0.46%—Tandoor Recipes3/26/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpoint exposes a hidden `?debug=true` query parameter that returns the complete raw SQL query being executed, including all table names, column names, JOIN relationships,…
AnalyzedHigh (7.5)0.53%—Tandoor Recipes3/26/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the default authentication backends. The AllAuth rate limiting configuration (ACCOUNT_RATE_LIMITS: login:…
AnalyzedHigh (8.1)0.38%—Tandoor Recipes3/26/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which causes Django to accept any value in the HTTP Host header without validation. The application uses request.build_absolute_uri() to generate…
AnalyzedMedium (6.5)0.48%—Tandoor Recipes3/26/20266/17/2026
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the FDC (USDA FoodData Central) search endpoint constructs an upstream API URL by directly interpolating the user-supplied `query` parameter into the URL string without URL-encoding. An…