CVE-2020-35659: Pi-Hole
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
The DNS query log in Pi-hole before 5.2.2 is vulnerable to stored XSS. An attacker with the ability to directly or indirectly query DNS with a malicious hostname can cause arbitrary JavaScript to execute when the Pi-hole administrator visits the Query Log or Long-term data Query Log page.
Affected products
- Pi-hole Pi-Hole: before 5.2.2 (fixed in 5.2.2)
Published 2020-12-24. Last modified 2026-06-17.