Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lookyloo:lookyloo:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 03 Dec 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lookyloo
Lookyloo lookyloo |
|
| Vendors & Products |
Lookyloo
Lookyloo lookyloo |
Tue, 02 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogonal-data feature. It is definitely exploitable from the popup view, but it is most probably also exploitable in many other places. This vulnerability is fixed in 1.35.3. | |
| Title | Lookyloo vulnerable to XSS due to lack of escaping in HTML elements passed to Datatables | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-02T19:14:43.987Z
Reserved: 2025-12-01T22:51:54.581Z
Link: CVE-2025-66460
Updated: 2025-12-02T19:14:40.550Z
Status : Analyzed
Published: 2025-12-02T19:15:53.163
Modified: 2025-12-05T14:57:46.010
Link: CVE-2025-66460
No data.
OpenCVE Enrichment
Updated: 2025-12-03T12:09:54Z