Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pi Hole

First CVE: Oct 9, 2019Active for: 7 yearsTotal CVEs: 69

Pi Hole is a network-wide ad-blocking and DNS management appliance deployed widely in home and small-business environments, built around a focused product architecture comprising the core filtering engine, FTL DNS resolver, and web administration interface. Vulnerabilities affecting this vendor arise across its DNS infrastructure and web-facing administrative components, reflecting the exposure inherent to a locally networked service that handles DNS queries and provides remote configuration access. Defenders should treat Pi Hole instances—particularly those exposed to untrusted networks—as requiring regular patching and should restrict administrative interface access to trusted segments. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
42
Total CVEs
More Total CVEs than 98% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
2.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Pi Hole over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 9, 2019
6 years ago
Most Recent CVE
May 5, 2026
81 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (42 CVEs).

42 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-8816HIGH
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
May 29, 20207.296YESYES
CVE-2020-11108HIGH
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the
May 11, 20208.883NOYES
CVE-2021-32706HIGH
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWi
Aug 4, 20218.871NOYES
CVE-2022-23513MEDIUM
Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the abilit
Dec 23, 20225.350NOYES
CVE-2025-34087HIGH
An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not prop
Jul 3, 20258.841NOYES
CVE-2026-39849HIGH
Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL acce
May 5, 20268.836NONO
CVE-2021-29449HIGH
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole
Apr 14, 20217.835NOYES
CVE-2019-13051HIGH
Pi-Hole 4.3 allows Command Injection.
Oct 9, 20198.834NONO
CVE-2025-53533MEDIUM
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and
Oct 27, 20256.133NOYES
CVE-2026-33765CRITICAL
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Inje
Mar 27, 20269.831NONO
View all 42 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products42 CVEs
48%
50%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local6 (14.3%)
Network36 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None24 (57.1%)
Unknown0 (0.0%)
Required18 (42.9%)
Privileges Required
Low22 (52.4%)
High5 (11.9%)
None15 (35.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (42 CVEs).

CISA KEV
1 CVE
2.4% of CVEs· 99th percentile
Metasploit
5 CVEs
11.9% of CVEs· 98th percentile
Nuclei
1 CVE
2.4% of CVEs· 95th percentile
ExploitDB
3 CVEs
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pi Hole.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pi Hole — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pi Hole's Products

View all 4 CNAs →

Top CWEs