Back to Database
Status published
Critical
CVE-2025-65095
Lookyloo is vulnerable due to improper user input sanitization
Vulnerability Description
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to version 1.35.1, there is potential cross-site scripting on index and tree page. This issue has been patched in version 1.35.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-65095
Credits & Attribution
No credits recorded in the NVD database.
References
More from Lookyloo
View All →CVE-2025-66460
Lookyloo vulnerable to XSS due to lack of escaping in HTML elements passed to Datatables
Medium
5.3
CVE-2025-66459
Lookyloo vulnerable to XSS due to unescaped error message passed to innerHTML
Medium
5.3
CVE-2025-66458
Lookyloo has multiple XSS due to unsafe use of f-strings in Markup
Medium
5.3
Affected Vendor
Lookyloo
View all reports →Affected Software
lookyloo
Vulnerable Versions:
< 1.35.1
Timeline
Official Publish:
November 19th, 2025
Last Modified:
November 20th, 2025
Added to House:
July 22nd, 2026