VYPR
High severity7.6NVD Advisory· Published Apr 15, 2021· Updated Jun 17, 2026

CVE-2021-29448

CVE-2021-29448

Description

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:pi-hole:ftldns:5.7:*:*:*:*:*:*:*
  • Pi Hole/Pi Hole2 versions
    cpe:2.3:a:pi-hole:pi-hole:5.2.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pi-hole:pi-hole:5.2.4:*:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:a:pi-hole:web_interface:*:*:*:*:*:*:*:*
    Range: <5.5
  • pi-hole/AdminLTEv5
    Range: <= 5.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.