CVEs we hold for Pi-hole
Records whose assigning authority named Pi-hole as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-50130Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`pi-hole
CVE-2026-44693Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Bufferpi-hole FTL
CVE-2026-41489Pi-hole: Local privilege escalation via config-controlled path in root-executed service hookspi-hole
CVE-2026-39849Pi-hole FTL remote code execution via newline injection in dns.interface configurationpi-hole FTL
CVE-2026-35521Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.hosts Newline Injectionpi-hole FTL
CVE-2026-35520Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.leaseTime Newline Injectionpi-hole FTL
CVE-2026-35519Pi-hole FTL affected by Remote Code Execution (RCE) via dns.hostRecord Newline Injectionpi-hole FTL
CVE-2026-35518Pi-hole FTL affected by Remote Code Execution (RCE) via dns.cnameRecords Newline Injectionpi-hole FTL
CVE-2026-35517Pi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline Injectionpi-hole FTL
CVE-2026-35491Pi-hole FTL: CLI API sessions can import Teleporter archives and modify configurationpi-hole FTL
CVE-2026-26953Pi-hole Web Interface has Stored HTML Injection via X-Forwarded-For Header in Active Sessions Tablepi-hole web
CVE-2026-26952Pi-hole Web Interface has Stored HTML Injection via Local DNS Records (CNAME/Hosts) in data-tag Attributepi-hole web
CVE-2025-59151Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injectionpi-hole web
CVE-2025-53533Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error pagepi-hole web
CVE-2025-34087Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command ExecutionPi-hole LLC Web
CVE-2025-32785Pi-hole Admin Interface vulnerable to persistent XSS on Subscribed lists group management (Adress Field)pi-hole web
CVE-2024-34361Pi-hole Blind Server-Side Request Forgery (SSRF) vulnerability can lead to Remote Code Execution (RCE)pi-hole
CVE-2022-23513Pi-Hole/AdminLTE vulnerable due to improper access control in queryads endpointpi-hole AdminLTE
35 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.