Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Web — Vulnerabilities & Security Advisories 28

All 28 CVE vulnerabilities found in Web, with AI-generated Chinese analysis, references, and POCs.

This page aggregates verified vulnerabilities affecting web application components and related web infrastructure products. It collects public security advisories and vulnerability disclosures specifically classified under the web product tag, covering the time range from 2010 through the present. Readers can use this view to track the security advisory history for major web vendors, analyze the frequency and impact of specific vulnerability classes in web environments, and review the cumulative exposure of particular web products over the selected period. The data is organized to support threat modeling, compliance audits, and risk assessment for web-facing assets.

Vendor: uTorrent

CVE ID Title CVSS Severity Published
CVE-2026-33405 Pi-hole has a Stored HTML Injection in queries.js CWE-79 3.1 Low 2026-04-06
CVE-2026-33406 Pi-hole has a Stored HTML attribute injection CWE-79 5.4 Medium 2026-04-06
CVE-2026-33404 Pi-hole has a Stored XSS / HTML injection in the Network page/Dashboard CWE-79 3.4 Low 2026-04-06
CVE-2026-33403 Pi-hole has a Reflected XSS / HTML injection in taillog.js CWE-79 6.1 Medium 2026-04-06
CVE-2026-33765 Pi-hole Web Interface has a Command Injection Vulnerability CWE-78 9.8 - 2026-03-27
CVE-2026-26953 Pi-hole Web Interface has Stored HTML Injection via X-Forwarded-For Header in Active Sessions Table CWE-20 5.4 Medium 2026-02-19
CVE-2026-26952 Pi-hole Web Interface has Stored HTML Injection via Local DNS Records (CNAME/Hosts) in data-tag Attribute CWE-20 5.4 Medium 2026-02-19
CVE-2025-55064 Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE-79 4.8 Medium 2025-12-29
CVE-2025-55063 Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE-79 4.8 Medium 2025-12-29
CVE-2025-55062 Priority - CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE-79 4.8 Medium 2025-12-29
CVE-2025-55061 Priority - CWE-434 Unrestricted Upload of File with Dangerous Type CWE-434 8.8 High 2025-12-29
CVE-2025-55060 Priority - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') CWE-601 6.1 Medium 2025-12-29
CVE-2025-59151 Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injection CWE-93 8.2 High 2025-10-27
CVE-2025-53533 Pi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page CWE-79 6.1AI Medium AI 2025-10-27
CVE-2025-32785 Pi-hole Admin Interface vulnerable to persistent XSS on Subscribed lists group management (Adress Field) CWE-79 5.4AI Medium AI 2025-10-27
CVE-2025-6791 Second order SQL injection available to user with low privilege CWE-89 8.8 High 2025-08-22
CVE-2025-4650 User with high privileges is able to introduce a SQLi using the Meta Service indicator page CWE-89 7.2 High 2025-08-22
CVE-2025-8744 CesiumLab Web lodmodels sql injection CWE-89 7.3 High 2025-08-08
CVE-2025-8220 Engeman Web Password Recovery RecoveryPass sql injection CWE-89 7.3 High 2025-07-27
CVE-2025-34087 Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution CWE-78 7.2AI High AI 2025-07-03
CVE-2025-4649 ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. CWE-755 4.9 Medium 2025-05-13
CVE-2025-4648 A user with elevated privileges can inject XSS by altering the content of a SVG media during the submit request. CWE-434 8.4 High 2025-05-13
CVE-2025-4647 A user with elevated privileges can bypass sanitization measures by replacing the content of an existing SVG CWE-79 8.4 High 2025-05-13
CVE-2025-4646 A high privilege user is able to create and use a valid admin API token in centreon-web CWE-863 7.2 High 2025-05-13
CVE-2022-4730 Graphite Web Absolute Time Range cross site scripting CWE-707 3.5 Low 2022-12-24
CVE-2022-4729 Graphite Web Template Name cross site scripting CWE-707 3.5 Low 2022-12-24
CVE-2022-4728 Graphite Web Cookie cross site scripting CWE-707 3.5 Low 2022-12-24
CVE-2018-25040 uTorrent Web HTTP RPC Server privileges management CWE-269 6.3 Medium 2022-06-17

All 28 known CVE vulnerabilities affecting Web with full Chinese analysis, references, and POCs where available.