Web Interface
Vendor:
First CVE: Apr 15, 2021 · Active for 5 years
16
Total CVEs
More Total CVEs than 92% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Web Interface over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2021
5 years ago
Most Recent CVE
Apr 6, 2026
109 days ago
CVE Severity & Scoring
Web Interface16 CVEs
69%
25%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (25.0%)
Unknown0 (0.0%)
Required12 (75.0%)
Privileges Required
Low5 (31.3%)
High1 (6.3%)
None10 (62.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-53533MEDIUM Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and | Oct 27, 2025 | 6.1 | 33 | NO | YES |
CVE-2026-33765CRITICAL Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Inje | Mar 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-59151HIGH Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface before 6.3 is vuln | Oct 27, 2025 | 8.2 | 26 | NO | NO |
CVE-2021-29448HIGH Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious | Apr 15, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-3706HIGH adminlte is vulnerable to Sensitive Cookie Without 'HttpOnly' Flag | Sep 15, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-23614HIGH Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and above, prior to 5.18.3 are vulnerable to Insufficient Session | Jan 26, 2023 | 8.8 | 22 | NO | NO |
CVE-2021-3811MEDIUM adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Sep 17, 2021 | 6.1 | 22 | NO | NO |
CVE-2021-3812MEDIUM adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Sep 17, 2021 | 6.1 | 21 | NO | NO |
CVE-2026-33406MEDIUM Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, configuration values from the | Apr 6, 2026 | 6.1 | 19 | NO | NO |
CVE-2026-33404MEDIUM Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. From 6.0 to before 6.5, client hostnames and IP addre | Apr 6, 2026 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.2% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Web Interface
Top CWEs
Versions
No cataloged versions.