threat
engine
.sh
Back
·
··:··
Home
/
Product
/
pi hole web interface
Product
pi hole web interface
25 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-33405
>= 6.0 and <= 6.4.1
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Fro
3.1
LOW
CVE-2026-33406
>= 6.0 and <= 6.4.1
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Fro
5.4
MEDIUM
CVE-2026-33404
>= 6.0 and <= 6.4.1
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Fro
3.4
LOW
CVE-2026-33403
>= 6.0 and <= 6.4.1
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Fro
6.1
MEDIUM
CVE-2026-33765
< 6.0
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Ver
9.8
CRITICAL
CVE-2026-26953
>= 6.0 and < 6.4.1
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Ve
5.4
MEDIUM
CVE-2026-26952
< 6.4.1
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Ver
5.4
MEDIUM
CVE-2025-59151
< 6.3
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking appli
8.2
HIGH
CVE-2025-53533
< 6.3
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking appli
6.1
MEDIUM
CVE-2025-32785
< 6.3
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking appli
5.4
MEDIUM
CVE-2023-23614
>= 4.0 and < 5.18.3
Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prio
8.8
HIGH
CVE-2022-41434
all versions
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component
6.1
MEDIUM
CVE-2022-41433
all versions
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component
4.8
MEDIUM
CVE-2022-41432
all versions
EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component
4.8
MEDIUM
CVE-2021-41175
< 5.8
Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generate
7.3
HIGH
CVE-2021-3812
< 5.6
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
6.1
MEDIUM
CVE-2021-3811
< 5.6
adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
6.1
MEDIUM
CVE-2021-3706
< 5.6
adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag
7.5
HIGH
CVE-2021-29448
< 5.5
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Adm
7.6
HIGH
CVE-2010-4515
all versions
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web
CVE-2009-2454
all versions
Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary w
CVE-2008-6830
all versions
The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's
CVE-2007-6477
<= 2.0
Cross-site scripting (XSS) vulnerability in the on-line help feature in Citrix Web Interface 2.0 and earlier, and NFuse, allows re
CVE-2006-6454
<= 2.1b
execInBackground.php in J-OWAMP Web Interface 2.1b and earlier allows remote attackers to execute arbitrary commands via shell met
CVE-2006-6453
all versions
PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated users to e
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin