Tandoor

Recipes

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 13.02.2026 18:29:10
  • Zuletzt bearbeitet 17.02.2026 16:10:27

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerability in the Cookmate recipe import feature of Tandoor Recipes. The appli...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 13.02.2026 18:27:08
  • Zuletzt bearbeitet 17.02.2026 16:07:02

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, a Path Traversal vulnerability in the RecipeImport workflow of Tandoor Recipes allows authenticated users with import permissions to ...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 19.09.2025 00:00:00
  • Zuletzt bearbeitet 03.10.2025 16:58:21

Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework of the API, which resulted in the User Profile API Endpoint containing two boolean values indicating whether a user is staff or ad...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 28.01.2025 16:15:41
  • Zuletzt bearbeitet 08.05.2025 18:45:54

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storage feature allows any user to enumerate the name and content of files on the server. This vulnerability is fixed in 1.5.28.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 28.01.2025 16:15:41
  • Zuletzt bearbeitet 08.05.2025 18:46:38

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerabili...

Exploit
  • EPSS 2.22%
  • Veröffentlicht 28.01.2025 16:15:40
  • Zuletzt bearbeitet 08.05.2025 18:44:44

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerab...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 01.03.2024 00:15:51
  • Zuletzt bearbeitet 19.05.2025 15:15:21

Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server. This is possible because the application is vulnerable to SSRF.

Exploit
  • EPSS 0.24%
  • Veröffentlicht 21.06.2022 10:15:08
  • Zuletzt bearbeitet 21.11.2024 06:47:55

In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Keyword, Food and Unit components. When a victim accesses the Keyword/Food/Unit endpoints, the XSS payload will trigger. A low privi...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 21.06.2022 09:15:08
  • Zuletzt bearbeitet 21.11.2024 06:47:55

In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parame...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 21.06.2022 08:15:07
  • Zuletzt bearbeitet 21.11.2024 06:47:55

In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functionality. When a victim accesses the food list page, then adds a new Food with a malicious javascript payload in the ‘Name’ parameter ...