Ftldns
Vendor:
First CVE: Apr 15, 2021 · Active for 5 years
8
Total CVEs
More Total CVEs than 87% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ftldns over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2021
5 years ago
Most Recent CVE
May 5, 2026
84 days ago
CVE Severity & Scoring
Ftldns8 CVEs
13%
88%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low7 (87.5%)
High0 (0.0%)
None1 (12.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39849HIGH Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL acce | May 5, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-35521HIGH FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Exe | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-35520HIGH FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Exe | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-35519HIGH FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Exe | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-35518HIGH FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Exe | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-35517HIGH FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL engine contains a Remote Code Exe | Apr 7, 2026 | 8.8 | 29 | NO | NO |
CVE-2021-29448HIGH Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious | Apr 15, 2021 | 8.8 | 26 | NO | NO |
CVE-2026-35491MEDIUM FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, Pi-hole FTL supports a CLI password feature (webs | Apr 7, 2026 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Ftldns
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.6 | 1 | 8.8 | 1.0% | 0 | 0 |
| 5.7 | 1 | 8.8 | 0.7% | 0 | 0 |