CVE-2026-33148 | TandoorRecipes recipes up to 2.5.x Parameter Query injection (GHSA-43p3-wx6h-9g7w)
A vulnerability identified as problematic has been detected in TandoorRecipes recipes up to 2.5.x. The affected element is an unknown function of the component Parameter Handler. Performing a manipulation of the argument Query results in injection.
This vulnerability was named CVE-2026-33148. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.