📦 Web Interface

by Pi Hole

🔍 What is Web Interface?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-59151

HIGH CVSS 8.2 Oct 27, 2025

Pi-hole Admin Interface before version 6.3 is vulnerable to CRLF injection, allowing attackers to inject arbitrary HTTP response headers by manipulating requests to .lp files. This can lead to session...

CVE-2021-41175

HIGH CVSS 7.3 Oct 26, 2021

CVE-2021-41175 is a cross-site scripting (XSS) vulnerability in Pi-hole's web interface that allows attackers to inject malicious scripts when adding clients via the groups-clients management page. Th...

CVE-2025-53533

MEDIUM CVSS 6.1 Oct 27, 2025

Pi-hole Admin Interface versions 6.2.1 and earlier contain a reflected cross-site scripting (XSS) vulnerability in the 404 error page. An attacker can craft malicious URLs that execute arbitrary JavaS...

CVE-2025-32785

MEDIUM CVSS 5.4 Oct 27, 2025

This vulnerability allows authenticated Pi-hole users to inject malicious JavaScript into the Address field when managing subscribed lists. When another user performs a gravity database update, the ma...