Vulnerabilities > Tandoor

DATE CVE VULNERABILITY TITLE RISK
2024-03-01 CVE-2024-0403 Unspecified vulnerability in Tandoor Recipes 1.5.10
Recipes version 1.5.10 allows arbitrary HTTP requests to be made through the server.
network
low complexity
tandoor
6.5
2022-06-19 CVE-2022-23071 Unspecified vulnerability in Tandoor Recipes
In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” functionality.
network
low complexity
tandoor
6.5