Lookyloo Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Lookyloo versions prior to 1.35.1. This issue arises from improper sanitization of user input, allowing HTML injection that could be exploited to execute scripts. On standard installations, the default Content Security Policy (CSP) mitigates the risk by preventing direct script execution, but the underlying vulnerability remains.

Impact

Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection and execution of malicious scripts in the user's browser.

Remediation

Users can upgrade to Lookyloo version 1.35.1 or later to address this vulnerability. If the default CSP configuration has been modified, it is recommended to revert to the original settings, as the default CSP effectively mitigates this issue.

Added: Nov 19, 2025, 6:32 PM
Updated: Nov 19, 2025, 7:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.0
remediation
7.7
relevance
1.1
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.