📦 Web Interface
by Pi Hole
🔍 What is Web Interface?
Description coming soon...
🛡️ Security Overview
Click on a severity to filter vulnerabilities
⚠️ Known Vulnerabilities
Pi-hole Admin Interface before version 6.3 is vulnerable to CRLF injection, allowing attackers to inject arbitrary HTTP response headers by manipulating requests to .lp files. This can lead to session...
CVE-2021-41175 is a cross-site scripting (XSS) vulnerability in Pi-hole's web interface that allows attackers to inject malicious scripts when adding clients via the groups-clients management page. Th...
Pi-hole Admin Interface versions 6.2.1 and earlier contain a reflected cross-site scripting (XSS) vulnerability in the 404 error page. An attacker can craft malicious URLs that execute arbitrary JavaS...
This vulnerability allows authenticated Pi-hole users to inject malicious JavaScript into the Address field when managing subscribed lists. When another user performs a gravity database update, the ma...