Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pi-hole:web_interface:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pi-hole
Pi-hole pi-hole Pi-hole web Interface |
|
| Vendors & Products |
Pi-hole
Pi-hole pi-hole Pi-hole web Interface |
Mon, 27 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions prior to 6.3 are vulnerable to cross-site scripting (XSS) via the Address field in the Subscribed Lists group management section. An authenticated user can inject malicious JavaScript by adding a payload to the Address field when creating or editing a list entry. The vulnerability is triggered when another user navigates to the Tools section and performs a gravity database update. The Address field does not properly sanitize input, allowing special characters and script tags to bypass validation. This has been patched in version 6.3. | |
| Title | Pi-hole Admin Interface vulnerable to persistent XSS on Subscribed lists group management (Adress Field) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-27T19:40:38.991Z
Reserved: 2025-04-10T12:51:12.279Z
Link: CVE-2025-32785
Updated: 2025-10-27T19:40:29.290Z
Status : Analyzed
Published: 2025-10-27T19:16:03.123
Modified: 2025-12-18T16:18:10.760
Link: CVE-2025-32785
No data.
OpenCVE Enrichment
Updated: 2025-10-28T10:24:31Z