VendorsPi-holeweb_interfaceall versions
Vulnerabilities

Pi-hole Web Interface

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2026-33765
Pi-hole Web Interface has a Command Injection Vulnerability
Published 2026-03-27 · Analyzed
9.8EPSS 0.018
CVE-2023-23614
Improper session handling of "Remember me for 7 days" functionality
Published 2023-01-26 · Modified
8.8EPSS 0.010
CVE-2021-29448
Stored DOM XSS in Pi-hole Admin Web Interface
Published 2021-04-15 · Modified
8.8EPSS 0.007
CVE-2025-59151
Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injection
Published 2025-10-27 · Analyzed
8.2EPSS 0.004
CVE-2021-3706
Sensitive Cookie Without 'HttpOnly' Flag in pi-hole/adminlte
Published 2021-09-15 · Modified
7.5EPSS 0.011
CVE-2021-41175
Stored XSS in Client Groups Management (Authenticated)
Published 2021-10-26 · Modified
7.3EPSS 0.009
CVE-2021-3811
Cross-site Scripting (XSS) - Reflected in pi-hole/adminlte
Published 2021-09-17 · Modified
6.7EPSS 0.006
CVE-2021-3812
Cross-site Scripting (XSS) - Reflected in pi-hole/adminlte
Published 2021-09-17 · Modified
6.7EPSS 0.006
CVE-2025-53533
Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page
Published 2025-10-27 · Analyzed
6.1EPSS 0.006
CVE-2026-33406
Pi-hole has a Stored HTML attribute injection
Published 2026-04-06 · Analyzed
6.1EPSS 0.004
CVE-2026-33403
Pi-hole has a Reflected XSS / HTML injection in taillog.js
Published 2026-04-06 · Analyzed
6.1EPSS 0.003
CVE-2026-33404
Pi-hole has a Stored XSS / HTML injection in the Network page/Dashboard
Published 2026-04-06 · Analyzed
6.1EPSS 0.002
CVE-2026-26953
Pi-hole Web Interface has Stored HTML Injection via X-Forwarded-For Header in Active Sessions Table
Published 2026-02-19 · Analyzed
5.4EPSS 0.004
CVE-2026-26952
Pi-hole Web Interface has Stored HTML Injection via Local DNS Records (CNAME/Hosts) in data-tag Attribute
Published 2026-02-19 · Analyzed
5.4EPSS 0.004
CVE-2025-32785
Pi-hole Admin Interface vulnerable to persistent XSS on Subscribed lists group management (Adress Field)
Published 2025-10-27 · Analyzed
5.4EPSS 0.002
CVE-2026-33405
Pi-hole has a Stored HTML Injection in queries.js
Published 2026-04-06 · Analyzed
4.8EPSS 0.003