VYPR

Lookyloo

by Lookyloo

Source repositories

CVEs (6)

  • CVE-2025-65095CriNov 19, 2025
    risk 0.54cvss epss 0.00

    Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to version 1.35.1, there is potential cross-site scripting on index and tree page. This issue has been patched in version 1.35.1.

  • CVE-2026-66913MedJul 28, 2026
    risk 0.00cvss epss 0.00

    Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially crafted ZIP, gzip, or zlib-compressed capture containing data that expands to a very large size during processing. Because the…

  • CVE-2026-66824CriJul 27, 2026
    risk 0.00cvss epss 0.00

    A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain values derived from captured…

  • CVE-2025-66460MedDec 2, 2025
    risk 0.00cvss 6.1epss 0.00

    Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogonal-data feature. It is definitely…

  • CVE-2025-66459MedDec 2, 2025
    risk 0.00cvss 6.1epss 0.00

    Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, a XSS vulnerability can be triggered when a user submits a list of URLs to capture, one of them contains a HTML element, and the…

  • CVE-2025-66458MedDec 2, 2025
    risk 0.00cvss 6.1epss 0.00

    Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, there are multiple XSS due to unsafe use of f-strings in Markup. The issue requires a malicious 3rd party server responding with a…