Pi-hole
Pi-hole WEB Interface: vulnerabilidades y CVE
Pi-hole WEB Interface tiene 16 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses10
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33405 | Media (4.8) | 0.29% | — | 6 abr 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, the formatInfo() function in queries.js renders data.upstream,… |
| CVE-2026-33406 | Media (6.1) | 0.37% | — | 6 abr 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, configuration values from the /api/config endpoint are placed… |
| CVE-2026-33404 | Media (6.1) | 0.25% | — | 6 abr 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, client hostnames and IP addresses from the FTL database are rendered… |
| CVE-2026-33403 | Media (6.1) | 0.32% | — | 6 abr 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, a reflected DOM-based XSS vulnerability in taillog.js allows an… |
| CVE-2026-33765 | Alta (8.9) | 1.8% | — | 27 mar 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the… |
| CVE-2026-26953 | Media (5.4) | 0.42% | — | 19 feb 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in the active sessions… |
| CVE-2026-26952 | Media (5.4) | 0.35% | — | 19 feb 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through the local DNS records… |
| CVE-2025-59151 | Alta (8.2) | 0.44% | — | 27 oct 2025 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vulnerable to Carriage Return Line Feed… |
| CVE-2025-53533 | Media (5.1) | 0.59% | — | 27 oct 2025 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected… |
| CVE-2025-32785 | Baja (2) | 0.25% | — | 27 oct 2025 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions prior to 6.3 are vulnerable to cross-site… |
| CVE-2023-23614 | Alta (8.8) | 0.97% | — | 26 ene 2023 | Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session Expiration. Improper use of admin… |
| CVE-2021-41175 | Media (5.4) | 0.90% | — | 26 oct 2021 | Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client… |
| CVE-2021-3812 | Media (6.1) | 0.55% | — | 17 sept 2021 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3811 | Media (6.1) | 0.55% | — | 17 sept 2021 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3706 | Alta (7.5) | 1.1% | — | 15 sept 2021 | adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag |
| CVE-2021-29448 | Alta (8.8) | 0.67% | — | 15 abr 2021 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS… |