CVE-2025-66460

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogonal-data feature. It is definitely exploitable from the popup view, but it is most probably also exploitable in many other places. This vulnerability is fixed in 1.35.3.
CVSS

No CVSS.

Configurations

No configuration.

History

02 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-02 19:15

Updated : 2025-12-02 19:15


NVD link : CVE-2025-66460

Mitre link : CVE-2025-66460

CVE.ORG link : CVE-2025-66460


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')