CVE-2025-23213

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
28/01/2025
Last modified:
08/05/2025

Description

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload feature allows to upload arbitrary files, including html and svg. Both can contain malicious content (XSS Payloads). This vulnerability is fixed in 1.5.28.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:* 1.5.28 (excluding)