CVE-2025-66460

MEDIUM

lookyloo < 1.35.3 - Stored Cross-Site Scripting via Datatables Orthogonal-Data Feature

Title source: llm
STIX 2.1

Description

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogonal-data feature. It is definitely exploitable from the popup view, but it is most probably also exploitable in many other places. This vulnerability is fixed in 1.35.3.

Scores

CVSS v3 6.1
EPSS 0.0015
EPSS Percentile 4.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
lookyloo/lookyloo < 1.35.3
Published Dec 02, 2025
Tracked Since Feb 18, 2026