Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tandoor

First CVE: Jun 19, 2022Active for: 4 yearsTotal CVEs: 22
38.9
VTI Score
Medium

Tandoor is a recipe management and meal-planning application that, despite a narrowly scoped product footprint, occupies a position among more prominent vulnerability-tracked entities. The vendor's disclosures cluster around web application input-handling and authorization weaknesses, including cross-site scripting, authorization bypass, and server-side request forgery, alongside exposure of sensitive metadata and dangerous method availability—patterns typical of web applications handling user-generated content and access controls. The concentration of vulnerabilities in a single, self-hosted product reflects the application's complexity as a multi-user system and the recurring challenges in validating and controlling user interactions across recipe data and sharing boundaries. Defenders deploying this application should prioritize input sanitization and access-control review during updates; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tandoor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2022
4 years ago
Most Recent CVE
Apr 10, 2026
108 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-23211CRITICAL
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server.
Jan 28, 20259.945NOYES
CVE-2026-35045HIGH
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes a
Apr 6, 20268.128NONO
CVE-2026-33149HIGH
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which ca
Mar 26, 20268.128NONO
CVE-2026-35488HIGH
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared
Apr 7, 20268.127NONO
CVE-2026-33152HIGH
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework wi
Mar 26, 20267.527NONO
CVE-2026-25991HIGH
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerabili
Feb 13, 20267.726NONO
CVE-2026-35489HIGH
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and uni
Apr 7, 20267.325NONO
CVE-2026-27460MEDIUM
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the rec
Apr 10, 20266.522NONO
CVE-2026-33153MEDIUM
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpoint exposes a hidden `?debug=tr
Mar 26, 20266.522NONO
CVE-2026-33148MEDIUM
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the FDC (USDA FoodData Central) search endpoint con
Mar 26, 20266.522NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
14%
55%
27%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (86.4%)
Unknown3 (13.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (86.4%)
High0 (0.0%)
Unknown3 (13.6%)
User Interaction
None16 (72.7%)
Unknown3 (13.6%)
Required3 (13.6%)
Privileges Required
Low11 (50.0%)
High3 (13.6%)
None5 (22.7%)
Unknown3 (13.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.5% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tandoor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tandoor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tandoor's Products

View all 4 CNAs →

Top CWEs