Tandoor is a recipe management and meal-planning application that, despite a narrowly scoped product footprint, occupies a position among more prominent vulnerability-tracked entities. The vendor's disclosures cluster around web application input-handling and authorization weaknesses, including cross-site scripting, authorization bypass, and server-side request forgery, alongside exposure of sensitive metadata and dangerous method availability—patterns typical of web applications handling user-generated content and access controls. The concentration of vulnerabilities in a single, self-hosted product reflects the application's complexity as a multi-user system and the recurring challenges in validating and controlling user interactions across recipe data and sharing boundaries. Defenders deploying this application should prioritize input sanitization and access-control review during updates; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tandoor over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-23211CRITICAL Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. | Jan 28, 2025 | 9.9 | 45 | NO | YES |
CVE-2026-35045HIGH Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the PUT /api/recipe/batch_update/ endpoint in Tandoor Recipes a | Apr 6, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-33149HIGH Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and including 2.5.3 set ALLOWED_HOSTS = '*' by default, which ca | Mar 26, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-35488HIGH Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, RecipeBookViewSet and RecipeBookEntryViewSet use CustomIsShared | Apr 7, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-33152HIGH Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, Tandoor Recipes configures Django REST Framework wi | Mar 26, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-25991HIGH Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, there is a Blind Server-Side Request Forgery (SSRF) vulnerabili | Feb 13, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-35489HIGH Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the POST /api/food/{id}/shopping/ endpoint reads amount and uni | Apr 7, 2026 | 7.3 | 25 | NO | NO |
CVE-2026-27460MEDIUM Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the rec | Apr 10, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-33153MEDIUM Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the Recipe API endpoint exposes a hidden `?debug=tr | Mar 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-33148MEDIUM Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior to 2.6.0, the FDC (USDA FoodData Central) search endpoint con | Mar 26, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tandoor.
Media articles that mention a CVE ID that affects a product developed by Tandoor — matched by CVE ID, not by vendor name.