CVE-2025-53533Disclosure(pi-hole / web_interface)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404 error page includes the requested path in the class attribute of the body tag without proper sanitization or escaping. An attacker can craft a URL containing an onload attribute that will execute arbitrary JavaScript code in the browser when a victim visits the malicious link. If an attacker sends a crafted pi-hole link to a victim and the victim visits it, attacker-controlled JavaScript code is executed in the browser of the victim. This has been patched in version 6.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_interface

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
web_interface

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-02: 1Technical Details · 2026-04-02: 104-02
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-53533 - medium 🚨 Pi-hole Reflected XSS in 404-Error Page > Pi-hole Admin Interface <= 6.2.1 contains a reflected XSS vulnerability on the 404 er... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-53533 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2025-53533 is a reflected XSS flaw in Pi‑hole admin pages (<= version 6.2.1). The text discloses the vulnerability type and affected version but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00022314
    960 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppi-holeweb_interface---

Explore more