lookyloo has 3 CVEs on record. The busiest recent month was December 2025 with 3. The median CVSS is 6.1 (medium). The most common weakness class is CWE-79 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- lookyloo 3
Worst active — by depth score
CVE-2025-66460Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other34CVE-2025-66459Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other34CVE-2025-66458Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other34
lookyloo vulnerabilities
CVEs affecting lookyloo, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2025-66460Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogo…
CVE-2025-66459Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, a XSS vulnerability can be triggered when a user submits a list of URLs to capture, one of …
CVE-2025-66458Medium· 6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, there are multiple XSS due to unsafe use of f-strings in Markup. The issue requires a malic…