vciy

CVEs we hold for Pi-hole

Records whose assigning authority named Pi-hole as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-50130Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`pi-hole
CVE-2026-44693Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Bufferpi-hole FTL
CVE-2026-41489Pi-hole: Local privilege escalation via config-controlled path in root-executed service hookspi-hole
CVE-2026-39849Pi-hole FTL remote code execution via newline injection in dns.interface configurationpi-hole FTL
CVE-2026-35521Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.hosts Newline Injectionpi-hole FTL
CVE-2026-35520Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.leaseTime Newline Injectionpi-hole FTL
CVE-2026-35519Pi-hole FTL affected by Remote Code Execution (RCE) via dns.hostRecord Newline Injectionpi-hole FTL
CVE-2026-35518Pi-hole FTL affected by Remote Code Execution (RCE) via dns.cnameRecords Newline Injectionpi-hole FTL
CVE-2026-35517Pi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline Injectionpi-hole FTL
CVE-2026-35491Pi-hole FTL: CLI API sessions can import Teleporter archives and modify configurationpi-hole FTL
CVE-2026-33765Pi-hole Web Interface has a Command Injection Vulnerabilitypi-hole web
CVE-2026-33727Pi-hole has a Local Privilege Escalation (post-compromise, pihole -> root).pi-hole
CVE-2026-33406Pi-hole has a Stored HTML attribute injectionpi-hole web
CVE-2026-33405Pi-hole has a Stored HTML Injection in queries.jspi-hole web
CVE-2026-33404Pi-hole has a Stored XSS / HTML injection in the Network page/Dashboardpi-hole web
CVE-2026-33403Pi-hole has a Reflected XSS / HTML injection in taillog.jspi-hole web
CVE-2026-26953Pi-hole Web Interface has Stored HTML Injection via X-Forwarded-For Header in Active Sessions Tablepi-hole web
CVE-2026-26952Pi-hole Web Interface has Stored HTML Injection via Local DNS Records (CNAME/Hosts) in data-tag Attributepi-hole web
CVE-2025-59151Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injectionpi-hole web
CVE-2025-53533Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error pagepi-hole web
CVE-2025-34087Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command ExecutionPi-hole LLC Web
CVE-2025-32785Pi-hole Admin Interface vulnerable to persistent XSS on Subscribed lists group management (Adress Field)pi-hole web
CVE-2024-34361Pi-hole Blind Server-Side Request Forgery (SSRF) vulnerability can lead to Remote Code Execution (RCE)pi-hole
CVE-2024-28247Pihole Authenticated Arbitrary File Read with root privilegespi-hole
CVE-2023-23614Improper session handling of "Remember me for 7 days" functionalitypi-hole AdminLTE
CVE-2022-31029Authenticated XSS in Pi-hole AdminLTEpi-hole AdminLTE
CVE-2022-23513Pi-Hole/AdminLTE vulnerable due to improper access control in queryads endpointpi-hole AdminLTE
CVE-2021-41175Stored XSS in Client Groups Management (Authenticated)pi-hole AdminLTE
CVE-2021-3812Cross-site Scripting (XSS) - Reflected in pi-hole/adminltepi-hole/adminlte
CVE-2021-3811Cross-site Scripting (XSS) - Reflected in pi-hole/adminltepi-hole/adminlte
CVE-2021-3706Sensitive Cookie Without 'HttpOnly' Flag in pi-hole/adminltepi-hole/adminlte
CVE-2021-32793Stored XSS Vulnerability in the Pi-hole Webinterfacepi-hole AdminLTE
CVE-2021-32706(Authenticated) Remote Code Execution Possible in Web Interface 5.5pi-hole AdminLTE
CVE-2021-29449Multiple Privilege Escalation Vulnerabilities Piholepi-hole
CVE-2021-29448Stored DOM XSS in Pi-hole Admin Web Interfacepi-hole AdminLTE

35 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.