CVE-2020-11108: Pi-Hole

High severity, CVSS 8.8. EPSS: 78.3% chance of exploitation in the next 30 days.

The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abused for Remote Code Execution by writing to a PHP file in the web directory. (Also, it can be used in conjunction with the sudo rule for the www-data user to escalate privileges to root.) The code error is in gravity_DownloadBlocklistFromUrl in gravity.sh.

Affected products

  • Pi-hole Pi-Hole: up to and including 4.4

Published 2020-05-11. Last modified 2026-06-17.