Vulnerabilities
Summary — last 7 days
New vulnerabilities2,577▼ 295 vs. last week
Critical / high1,354▲ 102 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
129 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.5) | 0.18% | — | Bootstrapped WP Recipe MakerAI | 9/23/2026 | 9/23/2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing unauthenticated users to have arbitrary shortcodes executed server side and to read the content of unpublished recipes. | |
| Deferred | High (8.2) | 0.24% | — | Bootstrapped WP Recipe MakerAI | 9/23/2026 | 9/23/2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from… | |
| Deferred | Medium (4.3) | 0.18% | — | Bootstrapped WP Recipe MakerAI | 9/23/2026 | 9/23/2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to retrieve the IDs and titles of other users' unpublished lists. | |
| Deferred | Medium (4.3) | 0.18% | — | Bootstrapped WP Recipe MakerAI | 9/23/2026 | 9/23/2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the full content of unpublished recipes. | |
| Deferred | Low (2.1) | 0.45% | — | Mealie-recipes MealieAI | 9/20/2026 | 9/21/2026 | A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the file mealie/routes/households/controller_group_recipe_actions.py of the component Recipe Action Trigger. Executing a manipulation of the argument url can lead to server-side request forgery. The… | |
| Deferred | Critical (9.1) | 0.68% | — | Bootstrapped WP Recipe MakerAI | 9/19/2026 | 9/21/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()` on every scalar field of the recipe's structured metadata array — including the… | |
| Deferred | Medium (5.4) | 0.24% | — | Bootstrapped WP Recipe MakerAI | 9/18/2026 | 9/18/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all versions up to, and including, 10.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Deferred | Medium (4.3) | 0.37% | — | Bootstrapped WP Recipe MakerAI | 9/9/2026 | 9/9/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Deferred | Medium (6.4) | 0.26% | — | Bootstrapped WP Recipe MakerAI | 9/1/2026 | 9/1/2026 | The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and including, 10.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Deferred | High (7.1) | 0.25% | — | Recipe Card Blocks FOR Gutenberg AND ElementorAI | 8/18/2026 | 8/20/2026 | Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | |
| Deferred | Medium (6.4) | 0.33% | — | Delicious RecipesAI | 7/16/2026 | 7/16/2026 | The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which interpolates the user-supplied href value… | |
| Deferred | High (8.5) | 0.36% | — | ZIP RecipesAI | 6/26/2026 | 6/26/2026 | Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions. | |
| Analyzed | High (8.8) | 0.43% | — | Joomboost Joomrecipe | 6/19/2026 | 8/19/2026 | Joomla Component JoomRecipe 1.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the category parameter. Attackers can send GET requests to the all-recipes endpoint with malicious SQL payloads in the category path segment to… | |
| Analyzed | High (8.8) | 0.46% | — | Joomboost Joomla Joomrecipe | 6/19/2026 | 8/19/2026 | Joomla JoomRecipe 1.0.4 component contains a blind SQL injection vulnerability in the search_author parameter on the search results page. Attackers can inject SQL code through POST requests to the search endpoint to extract database information using boolean-based blind SQL injection techniques. | |
| Deferred | Medium (6.4) | 0.35% | — | Recipe Card Blocks LiteAI | 6/8/2026 | 7/23/2026 | The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into… | |
| Analyzed | Medium (6.5) | 0.44% | — | Tandoor Recipes | 4/10/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated user to crash the server or make a significantly degrade its… | |
| Deferred | Medium (5.3) | 0.31% | — | Wpdelicious Delicious RecipesAI | 4/8/2026 | 7/24/2026 | Missing Authorization vulnerability in WP Delicious WP Delicious delicious-recipes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Delicious: from n/a through <= 1.9.5. | |
| Analyzed | High (7.3) | 0.32% | — | Tandoor Recipes | 4/7/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from request.data and passes them without validation to ShoppingListEntry.objects.create(). Invalid amount values (non-numeric… | |
| Analyzed | High (8.1) | 0.50% | — | Tandoor Recipes | 4/7/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class, but CustomIsShared.has_object_permission() returns True for all HTTP methods — including DELETE, PUT,… | |
| Analyzed | Medium (5.4) | 0.25% | — | Tandoor Recipes | 4/6/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authenticated users to inject arbitrary <style> tags into recipe step instructions. The bleach.clean() sanitizer explicitly whitelists the <style> tag, causing the backend to… | |
| Analyzed | High (8.1) | 0.38% | — | Tandoor Recipes | 4/6/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes allows any authenticated user within a Space to modify any recipe in that Space, including recipes marked as private by other users. This… | |
| Analyzed | High (7.7) | 0.46% | — | Tandoor Recipes | 3/26/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpoint exposes a hidden `?debug=true` query parameter that returns the complete raw SQL query being executed, including all table names, column names, JOIN relationships,… | |
| Analyzed | High (7.5) | 0.53% | — | Tandoor Recipes | 3/26/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the default authentication backends. The AllAuth rate limiting configuration (ACCOUNT_RATE_LIMITS: login:… | |
| Analyzed | High (8.1) | 0.38% | — | Tandoor Recipes | 3/26/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which causes Django to accept any value in the HTTP Host header without validation. The application uses request.build_absolute_uri() to generate… | |
| Analyzed | Medium (6.5) | 0.48% | — | Tandoor Recipes | 3/26/2026 | 6/17/2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the FDC (USDA FoodData Central) search endpoint constructs an upstream API URL by directly interpolating the user-supplied `query` parameter into the URL string without URL-encoding. An… |