CVE-2026-4239

LOW

Lagom WHMCS Template Datatables prototype pollution

Title source: cna

Description

A vulnerability was found in Lagom WHMCS Template up to 2.3.7. Impacted is an unknown function of the component Datatables. The manipulation results in improperly controlled modification of object prototype attributes. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 3.5
EPSS 0.0004
EPSS Percentile 11.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-1321 CWE-94
Status published
Products (8)
Lagom/WHMCS Template 2.3.0
Lagom/WHMCS Template 2.3.1
Lagom/WHMCS Template 2.3.2
Lagom/WHMCS Template 2.3.3
Lagom/WHMCS Template 2.3.4
Lagom/WHMCS Template 2.3.5
Lagom/WHMCS Template 2.3.6
Lagom/WHMCS Template 2.3.7
Published Mar 16, 2026
Tracked Since Mar 16, 2026