Squiz develops a focused line of enterprise content management and digital experience platforms, notably its Matrix product family, that serve as centralized systems for web publishing and site governance across organizations. The vendor's vulnerability profile centers on web-application and access-control weaknesses—including path traversal, cross-site scripting, authorization bypass, and deserialization flaws—that are characteristic of complex, user-facing CMS architectures, and a meaningful share of disclosures reach serious severity with moderate public exploit availability. Defenders should treat Squiz platform updates as relevant to their web-tier and content-publishing infrastructure; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Squiz over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19374CRITICAL An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 | Dec 11, 2019 | 9.1 | 28 | NO | NO |
CVE-2017-14198HIGH An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) vi | Nov 30, 2017 | 8.8 | 27 | NO | NO |
CVE-2019-19373HIGH An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary un | Dec 11, 2019 | 7.5 | 24 | NO | NO |
CVE-2017-14196HIGH An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the | Nov 30, 2017 | 7.5 | 24 | NO | NO |
CVE-2010-4901MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to inject arbitrary web script or HTML via the (1) height or (2 | Oct 8, 2011 | 4.3 | 23 | NO | YES |
CVE-2017-14197MEDIUM An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins. | Nov 30, 2017 | 6.1 | 20 | NO | NO |
CVE-2022-32277MEDIUM Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a request to change a user's contac | Sep 6, 2022 | 5.3 | 19 | NO | NO |
CVE-2006-5036MEDIUM MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary si | Sep 27, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-5037MEDIUM MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites wi | Sep 27, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-4635MEDIUM Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecifi | Sep 8, 2006 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Squiz.
Media articles that mention a CVE ID that affects a product developed by Squiz — matched by CVE ID, not by vendor name.