---
id: CVE-2025-53533
title: >-
  Pi-hole Admin Interface is a web interface for managing Pi-hole, a
  network-level advertisement and internet tracker blocking application
summary: >-
  Pi-hole Admin Interface is a web interface for managing Pi-hole, a
  network-level advertisement and internet tracker blocking application. Pi-hole
  Admin Interface versions 6.2.1 and earlier are vulnerable to reflected
  cross-site scripting…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: pi-hole
product: web_interface
affected:
  - web_interface < 6.3
patched:
  - web_interface 6.3
published: '2025-10-27'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53533'
references:
  - url: 'https://github.com/pi-hole/web/security/advisories/GHSA-w8f8-92rx-4f6w'
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.00591
epssPercentile: 0.46552
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/moezbouzayani9/Pi-hole-XSS-CVE-2025-53533'
  nuclei:
    - CVE-2025-53533
  checkedAt: '2026-10-08T11:32:03.423Z'
exploitAvailable: true
ingestedAt: '2026-10-08T11:31:27.645Z'
---

## Overview

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404 error page includes the requested path in the class attribute of the body tag without proper sanitization or escaping. An attacker can craft a URL containing an onload attribute that will execute arbitrary JavaScript code in the browser when a victim visits the malicious link. If an attacker sends a crafted pi-hole link to a victim and the victim visits it, attacker-controlled JavaScript code is executed in the browser of the victim. This has been patched in version 6.3.

## Affected

- `web_interface < 6.3`

## Remediation

Upgrade past the affected range:

- `web_interface 6.3`
