Pi Hole is a network-wide ad-blocking and DNS management appliance deployed widely in home and small-business environments, built around a focused product architecture comprising the core filtering engine, FTL DNS resolver, and web administration interface. Vulnerabilities affecting this vendor arise across its DNS infrastructure and web-facing administrative components, reflecting the exposure inherent to a locally networked service that handles DNS queries and provides remote configuration access. Defenders should treat Pi Hole instances—particularly those exposed to untrusted networks—as requiring regular patching and should restrict administrative interface access to trusted segments. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pi Hole over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8816HIGH Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease. | May 29, 2020 | 7.2 | 96 | YES | YES |
CVE-2020-11108HIGH The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the | May 11, 2020 | 8.8 | 83 | NO | YES |
CVE-2021-32706HIGH Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWi | Aug 4, 2021 | 8.8 | 71 | NO | YES |
CVE-2022-23513MEDIUM Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. In case of an attack, the threat actor will obtain the abilit | Dec 23, 2022 | 5.3 | 50 | NO | YES |
CVE-2025-34087HIGH An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, the domain parameter is not prop | Jul 3, 2025 | 8.8 | 41 | NO | YES |
CVE-2026-39849HIGH Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL acce | May 5, 2026 | 8.8 | 36 | NO | NO |
CVE-2021-29449HIGH Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole | Apr 14, 2021 | 7.8 | 35 | NO | YES |
CVE-2019-13051HIGH Pi-Hole 4.3 allows Command Injection. | Oct 9, 2019 | 8.8 | 34 | NO | NO |
CVE-2025-53533MEDIUM Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and | Oct 27, 2025 | 6.1 | 33 | NO | YES |
CVE-2026-33765CRITICAL Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Inje | Mar 27, 2026 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pi Hole.
Media articles that mention a CVE ID that affects a product developed by Pi Hole — matched by CVE ID, not by vendor name.