Lookyloo

Lookyloo

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 28.07.2026 12:19:20
  • Zuletzt bearbeitet 30.07.2026 16:55:34

Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially crafted ZIP, gzip, or zlib-compressed capture containing data that expands to a very large size duri...

  • EPSS 0.28%
  • Veröffentlicht 27.07.2026 19:58:28
  • Zuletzt bearbeitet 30.07.2026 16:55:34

A stored cross-site scripting vulnerability existed in the capture tree visualization page. The application embedded the serialized capture tree directly into an inline JavaScript block using the Jinja safe filter. Because the tree data can contain ...

  • EPSS 0.18%
  • Veröffentlicht 02.12.2025 18:34:45
  • Zuletzt bearbeitet 05.12.2025 14:57:46

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, Lookyloo passed improperly escaped values to cells rendered in datatables using the orthogonal-data feat...

  • EPSS 0.3%
  • Veröffentlicht 02.12.2025 18:32:59
  • Zuletzt bearbeitet 05.12.2025 14:58:10

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, a XSS vulnerability can be triggered when a user submits a list of URLs to capture, one of them contains...

  • EPSS 0.18%
  • Veröffentlicht 02.12.2025 18:30:56
  • Zuletzt bearbeitet 05.12.2025 14:58:21

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other. Prior to 1.35.3, there are multiple XSS due to unsafe use of f-strings in Markup. The issue requires a malicious 3rd part...