Pi-hole
This hub aggregates every CVE we track for Pi-hole, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
21
CVEs tracked
0
Critical
14
High
1
In CISA KEV
Severity distribution
HIGH14MEDIUM7
Monthly trend
1
0
0
0
0
0
0
0
0
0
0
1
0
0
1
0
0
0
0
0
1
1
0
1
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Pi-hole.
- CVE-2026-50130Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`8.8
- CVE-2026-41489Pi-hole: Local privilege escalation via config-controlled path in root-executed service hooks8.8
- CVE-2026-33727Pi-hole has a Local Privilege Escalation (post-compromise, pihole -> root).6.4
- CVE-2025-53533Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page6.1
- CVE-2025-34087Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution8.8
- CVE-2024-44069Pi-hole before 6 allows unauthenticated admin/api.php?setTempUnit= calls to change the temperature units of the web dashboard. NOTE: the supplier reportedly does "not consider the bug a security is...7.5
- CVE-2024-34361Pi-hole Blind Server-Side Request Forgery (SSRF) vulnerability can lead to Remote Code Execution (RCE)8.5
- CVE-2024-28247Pihole Authenticated Arbitrary File Read with root privileges7.6
- CVE-2021-32793Stored XSS Vulnerability in the Pi-hole Webinterface5.7
- CVE-2021-32706(Authenticated) Remote Code Execution Possible in Web Interface 5.57.6
- CVE-2021-29448Stored DOM XSS in Pi-hole Admin Web Interface7.6
- CVE-2021-29449Multiple Privilege Escalation Vulnerabilities Pihole6.3
- CVE-2020-35592Pi-hole 5.0, 5.1, and 5.1.1 allows XSS via the Options header to the admin/ URI. A remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and...5.4
- CVE-2020-35591Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie valu...5.4
- CVE-2020-35659The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to e...6.1
Product normalization is registry-driven with AI assist and human review. How it works