← Back

Pi Hole

pi-hole

43 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Pi Hole
pi-hole
Web Interface
web_interface
Ftldns
ftldns
Adminlte
adminlte

CVEs (43)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pi Hole
1Pi Hole
Jun 17, 2026
May 29, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
1Pi Hole
1Pi Hole
Jun 17, 2026
May 11, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in...Show more
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.Show less
1Pi Hole
1Pi Hole
Jun 17, 2026
Oct 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Pi-Hole 4.3 allows Command Injection.