Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lodash

First CVE: Jun 7, 2018Active for: 8 yearsTotal CVEs: 10
36.7
VTI Score
Medium

Lodash is a widely embedded utility library that provides functional programming helpers across countless JavaScript applications and frameworks, despite its narrow product footprint. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity and a moderate tendency toward public exploit availability; the exposure recurs through prototype-pollution flaws, code-injection risks, and uncontrolled resource consumption that reflect the library's deep involvement in object manipulation and dynamic code evaluation. Defenders should prioritize inventory of applications bundling this library, since a single flaw in Lodash can propagate across an enormous supply-chain footprint; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lodash over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2018
8 years ago
Most Recent CVE
Mar 31, 2026
115 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-23337HIGH
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Feb 15, 20217.249NOYES
CVE-2026-4800CRITICAL
Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation
Mar 31, 20269.842NONO
CVE-2019-10744CRITICAL
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype usin
Jul 26, 20199.131NONO
CVE-2025-13465MEDIUM
Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete met
Jan 21, 20265.329NONO
CVE-2020-8203HIGH
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Jul 15, 20207.427NONO
CVE-2026-2950MEDIUM
Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodas
Mar 31, 20265.324NONO
CVE-2019-1010266MEDIUM
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker
Jul 17, 20196.524NONO
CVE-2018-3721MEDIUM
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicio
Jun 7, 20186.523NONO
CVE-2020-28500MEDIUM
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Feb 15, 20215.321NONO
CVE-2018-16487MEDIUM
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object
Feb 1, 20195.621NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
20%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (20.0%)
High1 (10.0%)
None7 (70.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lodash.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lodash — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lodash's Products

View all 4 CNAs →

Top CWEs