CVE-2025-53533 - CVE House
Back to Database
Status published Medium CVE-2025-53533

Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page

Vulnerability Description

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole Admin Interface versions 6.2.1 and earlier are vulnerable to reflected cross-site scripting (XSS) via a malformed URL path. The 404 error page includes the requested path in the class attribute of the body tag without proper sanitization or escaping. An attacker can craft a URL containing an onload attribute that will execute arbitrary JavaScript code in the browser when a victim visits the malicious link. If an attacker sends a crafted pi-hole link to a victim and the victim visits it, attacker-controlled JavaScript code is executed in the browser of the victim. This has been patched in version 6.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53533

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

web
Vulnerable Versions:
< 6.3

Timeline

Official Publish: October 27th, 2025
Last Modified: October 27th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)