CVE Tools

Pi-hole

14 CVEs tracked since 2021. Since Sep 2021, none of them reached CISA KEV.

Pi-hole CVEs per month

Sep 2021 to Apr 2026. Point at a month, or focus the strip and use the arrow keys.
Pi-hole CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0930
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04110

Products

The products that kept showing up in Pi-hole's monthly top three, with their CVEs summed over those months.

  1. Web Interface72 months
  2. Ftl61 month
  3. Ftldns61 month
  4. Pi-hole/adminlte31 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Pi-hole.

  1. CVE-2026-50130Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`8.8
  2. CVE-2026-44693Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Buffer8.8
  3. CVE-2026-41489Pi-hole: Local privilege escalation via config-controlled path in root-executed service hooks8.8
  4. CVE-2026-39849Pi-hole FTL remote code execution via newline injection in dns.interface configuration8.8
  5. CVE-2026-35521Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.hosts Newline Injection8.8
  6. CVE-2026-35520Pi-hole FTL affected by Remote Code Execution (RCE) via dhcp.leaseTime Newline Injection8.8
  7. CVE-2026-35519Pi-hole FTL affected by Remote Code Execution (RCE) via dns.hostRecord Newline Injection8.8
  8. CVE-2026-35518Pi-hole FTL affected by Remote Code Execution (RCE) via dns.cnameRecords Newline Injection8.8
  9. CVE-2026-35517Pi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline Injection8.8
  10. CVE-2026-35491Pi-hole FTL: CLI API sessions can import Teleporter archives and modify configuration6.1
  11. CVE-2026-33405Pi-hole has a Stored HTML Injection in queries.js3.1
  12. CVE-2026-33727Pi-hole has a Local Privilege Escalation (post-compromise, pihole -> root).6.4
  13. CVE-2026-33406Pi-hole has a Stored HTML attribute injection5.4
  14. CVE-2026-33404Pi-hole has a Stored XSS / HTML injection in the Network page/Dashboard3.4
  15. CVE-2026-33403Pi-hole has a Reflected XSS / HTML injection in taillog.js6.1

The record

Peak rank
#92 in Apr 2026
Busiest month shown
Apr 2026, 11 CVEs
Months with a KEV entry
0 since Sep 2021
Monthly snapshots
2 since 2021
Pi-hole's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store