Slimframework is a lightweight PHP microframework and its related middleware components, with vulnerabilities clustering around code-generation and request-handling layers. The durable pattern centers on improper code injection and interpretation conflicts, reflecting the framework's role in dynamically processing and routing user-supplied input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Slimframework over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2171HIGH Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data. | Mar 30, 2015 | 7.5 | 25 | NO | NO |
CVE-2023-30536MEDIUM slim/psr7 is a PSR-7 implementation for use with Slim 4. In versions prior to 1.6.1 an attacker could sneak in a newline (\n) into both the header names and values. While the speci | Apr 17, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Slimframework.
Media articles that mention a CVE ID that affects a product developed by Slimframework — matched by CVE ID, not by vendor name.