← Back

Pi Hole

pi-hole

42 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Pi Hole
pi-hole
Web Interface
web_interface
Ftldns
ftldns
Adminlte
adminlte

CVEs (42)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pi Hole
1Pi Hole
Jun 17, 2026
May 11, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in...Show more
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.Show less
1Pi Hole
1Pi Hole
Jun 17, 2026
Oct 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Pi-Hole 4.3 allows Command Injection.