CVE-2025-65095: Lookyloo

Critical severity, CVSS 9.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to version 1.35.1, there is potential cross-site scripting on index and tree page. This issue has been patched in version 1.35.1.

Affected products

  • Lookyloo Lookyloo: before 1.35.1 (fixed in 1.35.1)

Published 2025-11-19. Last modified 2026-06-17.