lookyloo vulnerabilities
CVEs whose affected-version data names the lookyloo package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-66460Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogo…
CVE-2025-66459Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, a XSS vulnerability can be triggered when a user submits a list of URLs to capture, one of …
CVE-2025-66458Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, there are multiple XSS due to unsafe use of f-strings in Markup. The issue requires a malic…