VendorsPi-holeftldnsall versions
Vulnerabilities

Pi-hole FTLDNS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-35517
Pi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline Injection
Published 2026-04-07 · Analyzed
8.8EPSS 0.010
CVE-2026-35518
Pi-hole FTL affected by Remote Code Execution (RCE) via dns.cnameRecords Newline Injection
Published 2026-04-07 · Analyzed
8.8EPSS 0.010
CVE-2026-35520
Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.leaseTime Newline Injection
Published 2026-04-07 · Analyzed
8.8EPSS 0.010
CVE-2026-35521
Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.hosts Newline Injection
Published 2026-04-07 · Analyzed
8.8EPSS 0.010
CVE-2026-35519
Pi-hole FTL affected by Remote Code Execution (RCE) via dns.hostRecord Newline Injection
Published 2026-04-07 · Analyzed
8.8EPSS 0.010
CVE-2026-39849
Pi-hole FTL remote code execution via newline injection in dns.interface configuration
Published 2026-05-05 · Analyzed
8.8EPSS 0.010
CVE-2021-29448
Stored DOM XSS in Pi-hole Admin Web Interface
Published 2021-04-15 · Modified
8.8EPSS 0.007
CVE-2026-35491
Pi-hole FTL: CLI API sessions can import Teleporter archives and modify configuration
Published 2026-04-07 · Analyzed
6.1EPSS 0.002