Vulnerability record · CVE-2021-29448 · published 15 April 2021
CVE-2021-29448: Pi-hole ftldns cross-site scripting vulnerability
Pi Hole · Ftldns
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.
Description
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/pi-hole/AdminLTE/security/advisories/GHSA-cwwf-93p7-73j9 | ExploitThird Party Advisory |
| https://github.com/pi-hole/AdminLTE/security/advisories/GHSA-cwwf-93p7-73j9 | ExploitThird Party Advisory |
Track CVE-2021-29448 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29448), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.