CVE-2026-26952 | pi-hole web up to 6.4.0 populateDataTable cross site scripting (GHSA-6xp4-jw73-f4qp)
A vulnerability, which was classified as problematic, has been found in pi-hole web up to 6.4.0. This affects the function populateDataTable. This manipulation causes basic cross site scripting.
This vulnerability is tracked as CVE-2026-26952. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.