Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pi-hole:web_interface:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 28 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pi-hole
Pi-hole pi-hole Pi-hole web Interface |
|
| Vendors & Products |
Pi-hole
Pi-hole pi-hole Pi-hole web Interface |
Mon, 27 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404 error page includes the requested path in the class attribute of the body tag without proper sanitization or escaping. An attacker can craft a URL containing an onload attribute that will execute arbitrary JavaScript code in the browser when a victim visits the malicious link. If an attacker sends a crafted pi-hole link to a victim and the victim visits it, attacker-controlled JavaScript code is executed in the browser of the victim. This has been patched in version 6.3. | |
| Title | Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-27T19:19:08.837Z
Reserved: 2025-07-02T15:15:11.515Z
Link: CVE-2025-53533
Updated: 2025-10-27T19:18:59.029Z
Status : Analyzed
Published: 2025-10-27T19:16:04.003
Modified: 2025-12-18T16:23:06.350
Link: CVE-2025-53533
No data.
OpenCVE Enrichment
Updated: 2025-10-28T10:24:24Z