CVE-2026-27460
- EPSS 0.04%
- Veröffentlicht 10.04.2026 19:16:21
- Zuletzt bearbeitet 14.04.2026 17:29:17
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated u...
CVE-2026-35489
- EPSS 0.05%
- Veröffentlicht 07.04.2026 14:53:18
- Zuletzt bearbeitet 14.04.2026 20:13:00
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and unit directly from request.data and passes them without validation to Sho...
CVE-2026-35488
- EPSS 0.04%
- Veröffentlicht 07.04.2026 14:51:25
- Zuletzt bearbeitet 17.04.2026 19:46:09
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared as an alternative permission class, but CustomIsShared.has_object_per...
CVE-2026-35046
- EPSS 0.03%
- Veröffentlicht 06.04.2026 17:20:00
- Zuletzt bearbeitet 10.04.2026 18:33:43
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tandoor Recipes allows authenticated users to inject arbitrary <style> tags into recipe step instructions. The bleach.clean() sanitiz...
CVE-2026-35045
- EPSS 0.03%
- Veröffentlicht 06.04.2026 17:17:57
- Zuletzt bearbeitet 10.04.2026 18:32:17
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes allows any authenticated user within a Space to modify any recipe in th...
CVE-2026-33152
- EPSS 0.07%
- Veröffentlicht 26.03.2026 19:07:39
- Zuletzt bearbeitet 30.03.2026 19:18:18
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework with BasicAuthentication as one of the default authentication backends. ...
CVE-2026-33153
- EPSS 0.04%
- Veröffentlicht 26.03.2026 19:06:16
- Zuletzt bearbeitet 30.03.2026 19:16:16
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpoint exposes a hidden `?debug=true` query parameter that returns the complete raw SQL query being exec...
CVE-2026-33148
- EPSS 0.05%
- Veröffentlicht 26.03.2026 19:04:25
- Zuletzt bearbeitet 30.03.2026 19:26:49
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the FDC (USDA FoodData Central) search endpoint constructs an upstream API URL by directly interpolating the user-supplie...
CVE-2026-29055
- EPSS 0.04%
- Veröffentlicht 26.03.2026 19:03:06
- Zuletzt bearbeitet 30.03.2026 19:27:34
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the image processing pipeline in Tandoor Recipes explicitly skips EXIF metadata stripping, image rescaling, and size vali...
CVE-2026-28503
- EPSS 0.05%
- Veröffentlicht 26.03.2026 18:55:53
- Zuletzt bearbeitet 30.03.2026 19:28:48
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the `SyncViewSet.query_synced_folder()` action in `cookbook/views/api.py` (line 903) fetches a Sync object using `get_obj...