Denial of Service Vulnerability in Lagom WHMCS Template from Vendor
CVE-2026-6601
Key Information:
- Vendor
Lagom
- Status
- Vendor
- CVE Published:
- 20 April 2026
Badges
What is CVE-2026-6601?
A resource consumption vulnerability has been discovered in the Lagom WHMCS Template, affecting versions up to 2.4.2. This vulnerability is associated with a particular function within the Datatables component, enabling potential remote exploitation. The lack of response from the vendor following the disclosure highlights the urgency for users to secure their installations against unauthorized access and service disruption.
Affected Version(s)
WHMCS Template 2.4.0
WHMCS Template 2.4.1
WHMCS Template 2.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
