VYPR

Pi Hole

by Pi Hole

Source repositories

CVEs (39)

  • CVE-2020-11108HigMay 11, 2020
    risk 0.66cvss 8.8epss 0.78

    The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to…

  • CVE-2025-34087HigJul 3, 2025
    risk 0.61cvss 8.8epss 0.05

    An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not properly sanitized, allowing an attacker to append OS commands to the domain string. These commands are…

  • CVE-2020-8816HigKEVMay 29, 2020
    risk 0.61cvss 7.2epss 0.78

    Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

  • CVE-2023-23614HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin WEBPASSWORD hash as "Remember me for 7 days" cookie value makes…

  • CVE-2021-32706HigAug 4, 2021
    risk 0.57cvss 7.6epss 0.60

    Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character through that can be used to execute code,…

  • CVE-2020-14162HigJul 30, 2020
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Pi-Hole through 5.0. The local www-data user has sudo privileges to execute the pihole core script as root without a password, which could allow an attacker to obtain root access via shell metacharacters to this script's setdns command.

  • CVE-2020-12620HigJul 30, 2020
    risk 0.51cvss 7.8epss 0.01

    Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).

  • CVE-2026-44693HigJun 10, 2026
    risk 0.50cvss 8.8epss 0.00

    Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session management subsystem, introduced with the v6.0 rewrite of the embedded CivetWeb-based…

  • CVE-2026-41489HigMay 11, 2026
    risk 0.50cvss 8.8epss 0.00

    Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to before Core 6.4.2 and FTL 6.6.1, two shell scripts executed as root by systemd (pihole-FTL-prestart.sh and pihole-FTL-poststop.sh) read the files.pid…

  • CVE-2026-35521HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.01

    FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP hosts configuration parameter (dhcp.hosts). This…

  • CVE-2026-35520HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.01

    FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DHCP lease time configuration parameter (dhcp.leaseTime). This…

  • CVE-2026-35519HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.01

    FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the DNS host record configuration parameter (dns.hostRecord). This…

  • CVE-2026-35517HigApr 7, 2026
    risk 0.50cvss 8.8epss 0.01

    FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Execution (RCE) vulnerability in the upstream DNS servers configuration parameter (dns.upstreams).…

  • CVE-2021-29448HigApr 15, 2021
    risk 0.49cvss 7.6epss 0.01

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch…

  • CVE-2025-59151HigOct 27, 2025
    risk 0.46cvss 8.2epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable to Carriage Return Line Feed (CRLF) injection. When a request is made to a file ending with…

  • CVE-2021-29449MedApr 14, 2021
    risk 0.44cvss 6.3epss 0.02

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

  • CVE-2026-33727MedApr 6, 2026
    risk 0.42cvss 6.4epss 0.00

    Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privilege-escalation vulnerability allows code execution as root from the low-privilege pihole account. Important context: the pihole account uses nologin, so this…

  • CVE-2022-23513MedDec 23, 2022
    risk 0.41cvss 5.3epss 0.40

    Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the ability to perform an unauthorized query for blocked domains on `queryads` endpoint. In the case of…

  • CVE-2021-32793MedAug 4, 2021
    risk 0.37cvss 5.7epss 0.01

    Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the function to add domains to blocklists or allowlists is vulnerable to a stored cross-site-scripting vulnerability.…

  • CVE-2026-33406MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, configuration values from the /api/config endpoint are placed directly into HTML value="" attributes without escaping in…

Page 1 of 2