VYPR

Pi Hole

by Pi Hole

Source repositories

CVEs (39)

  • CVE-2025-32785MedOct 27, 2025
    risk 0.35cvss 5.4epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions prior to 6.3 are vulnerable to cross-site scripting (XSS) via the Address field in the Subscribed Lists…

  • CVE-2020-35592MedFeb 18, 2021
    risk 0.35cvss 5.4epss 0.01

    Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against other users and steal the…

  • CVE-2020-35591MedFeb 18, 2021
    risk 0.35cvss 5.4epss 0.01

    Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes…

  • CVE-2025-53533MedOct 27, 2025
    risk 0.33cvss 6.1epss 0.01

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404…

  • CVE-2026-33405LowApr 6, 2026
    risk 0.20cvss 3.1epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, the formatInfo() function in queries.js renders data.upstream, data.client.ip, and data.ede.text into HTML without escaping when…

  • CVE-2019-13051HigOct 9, 2019
    risk 0.01cvss 8.8epss 0.12

    Pi-Hole 4.3 allows Command Injection.

  • CVE-2026-50130HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.00

    Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered…

  • CVE-2026-26953MedFeb 19, 2026
    risk 0.00cvss 5.4epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions table located on the API settings page, allowing an attacker…

  • CVE-2026-26952MedFeb 19, 2026
    risk 0.00cvss 5.4epss 0.00

    Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through the local DNS records configuration page, which allows an authenticated…

  • CVE-2024-44069HigAug 19, 2024
    risk 0.00cvss 7.5epss 0.00

    Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security issue" but the specific motivation for letting arbitrary persons change the value…

  • CVE-2024-34361HigJul 5, 2024
    risk 0.00cvss 8.5epss 0.03

    Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an authenticated user to make internal requests to the server via the `gravity_DownloadBlocklistFromUrl()`…

  • CVE-2024-28247HigMar 27, 2024
    risk 0.00cvss 7.6epss 0.01

    The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole that allows an authenticated user on the platform to read internal server files arbitrarily, and because the…

  • CVE-2022-31029MedJul 7, 2022
    risk 0.00cvss 5.9epss 0.00

    AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `` in the field marked with "Domain to look for" and hitting enter (or clicking on any of the buttons) will execute the script. The user…

  • CVE-2021-41175HigOct 26, 2021
    risk 0.00cvss 7.3epss 0.01

    Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was…

  • CVE-2021-3812MedSep 17, 2021
    risk 0.00cvss 6.1epss 0.01

    adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3811MedSep 17, 2021
    risk 0.00cvss 6.1epss 0.01

    adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2021-3706HigSep 15, 2021
    risk 0.00cvss 7.5epss 0.01

    adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag

  • CVE-2020-35659MedDec 24, 2020
    risk 0.00cvss 6.1epss 0.01

    The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query…

  • CVE-2020-14971HigJun 23, 2020
    risk 0.00cvss 7.8epss 0.01

    Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them. This occurs in settings.php. To exploit this, an attacker would request a backup of limited files via teleporter.php. These are…

Page 2 of 2