← Vulnerability feed

Vulnerability record · CVE-2021-29448 · published 15 April 2021

CVE-2021-29448: Pi-hole ftldns cross-site scripting vulnerability

Pi Hole · Ftldns

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.

8.8 CVSS 3.1 High EPSS 0.67% · top 50.1% CWE-79 · Cross-site scripting
8.8CVSS 3.1 base score, v2 5.8
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-29448 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2020-8816Pi-hole AdminLTE DHCP static lease OS command injectionPi-hole Web v4.3.2 (AdminLTE) fails to sanitize the MAC address field of a DHCP static lease, allowing OS command injection. A privileged dashboard u…KEVEPSS 78%analysed9.0CVE-2025-34087Pi-hole os command injection vulnerabilityAn authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allowlist via the web interface, t…EPSS 7.0%8.9CVE-2026-33765Pi-hole web interface os command injection vulnerabilityPi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 …EPSS 1.8%8.8CVE-2026-50130Pi-hole vulnerabilityPi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with cod…EPSS 0.26%8.8CVE-2026-35517Pi-hole ftldns os command injection vulnerabilityFTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…EPSS 1.0%8.8CVE-2026-35518Pi-hole ftldns os command injection vulnerabilityFTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…EPSS 1.0%8.8CVE-2026-35519Pi-hole ftldns os command injection vulnerabilityFTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…EPSS 1.00%8.8CVE-2026-35520Pi-hole ftldns os command injection vulnerabilityFTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to before 6.6, the Pi-hole FTL en…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2021-29448), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.