Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Squiz

First CVE: Sep 8, 2006Active for: 20 yearsTotal CVEs: 10
32.3
VTI Score
Medium

Squiz develops a focused line of enterprise content management and digital experience platforms, notably its Matrix product family, that serve as centralized systems for web publishing and site governance across organizations. The vendor's vulnerability profile centers on web-application and access-control weaknesses—including path traversal, cross-site scripting, authorization bypass, and deserialization flaws—that are characteristic of complex, user-facing CMS architectures, and a meaningful share of disclosures reach serious severity with moderate public exploit availability. Defenders should treat Squiz platform updates as relevant to their web-tier and content-publishing infrastructure; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Squiz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 8, 2006
19 years ago
Most Recent CVE
Sep 6, 2022
1,417 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-19374CRITICAL
An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1
Dec 11, 20199.128NONO
CVE-2017-14198HIGH
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) vi
Nov 30, 20178.827NONO
CVE-2019-19373HIGH
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary un
Dec 11, 20197.524NONO
CVE-2017-14196HIGH
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the
Nov 30, 20177.524NONO
CVE-2010-4901MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2
Oct 8, 20114.323NOYES
CVE-2017-14197MEDIUM
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins.
Nov 30, 20176.120NONO
CVE-2022-32277MEDIUM
Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contac
Sep 6, 20225.319NONO
CVE-2006-5036MEDIUM
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary si
Sep 27, 20066.818NONO
CVE-2006-5037MEDIUM
MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites wi
Sep 27, 20066.818NONO
CVE-2006-4635MEDIUM
Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecifi
Sep 8, 20066.518NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
30%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (60.0%)
Unknown4 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (60.0%)
High0 (0.0%)
Unknown4 (40.0%)
User Interaction
None5 (50.0%)
Unknown4 (40.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None5 (50.0%)
Unknown4 (40.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Squiz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Squiz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Squiz's Products

View all 1 CNAs →

Top CWEs