Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lookyloo:lookyloo:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 03 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lookyloo
Lookyloo lookyloo |
|
| Vendors & Products |
Lookyloo
Lookyloo lookyloo |
Tue, 02 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, there are multiple XSS due to unsafe use of f-strings in Markup. The issue requires a malicious 3rd party server responding with a JSON document containing JS code in a script element. This vulnerability is fixed in 1.35.3. | |
| Title | Lookyloo has multiple XSS due to unsafe use of f-strings in Markup | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-02T19:26:59.655Z
Reserved: 2025-12-01T22:51:54.581Z
Link: CVE-2025-66458
Updated: 2025-12-02T19:26:55.393Z
Status : Analyzed
Published: 2025-12-02T19:15:52.850
Modified: 2025-12-05T14:58:21.437
Link: CVE-2025-66458
No data.
OpenCVE Enrichment
Updated: 2025-12-03T12:09:57Z