Getlaminas maintains a focused portfolio of PHP web framework and HTTP-handling libraries, including components such as Laminas Diactoros, Laminas Form, and Laminas HTTP that are embedded across server applications. The recurring vulnerability surface centers on input-handling and deserialization weaknesses—cross-site scripting, untrusted deserialization, input validation, and HTTP request smuggling—reflecting the parsing and user-input demands typical of web middleware and form-processing libraries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getlaminas over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3007CRITICAL Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, rel | Jan 4, 2021 | 9.8 | 81 | NO | YES |
CVE-2022-31109MEDIUM laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP message factory interfaces. Applications that use Diactoros, and | Aug 1, 2022 | 6.1 | 21 | NO | NO |
CVE-2023-29530MEDIUM Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP request | Apr 24, 2023 | 6.5 | 17 | NO | NO |
CVE-2022-23598MEDIUM laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messages via the `formElementErrors()` view helper shipped with la | Jan 28, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getlaminas.
Media articles that mention a CVE ID that affects a product developed by Getlaminas — matched by CVE ID, not by vendor name.