Vulnerabilities > Squiz > High

DATE CVE VULNERABILITY TITLE RISK
2019-12-11 CVE-2019-19373 Deserialization of Untrusted Data vulnerability in Squiz Matrix
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during processing of a Remote Content page type.
network
low complexity
squiz CWE-502
7.5
2017-11-30 CVE-2017-14198 Code Injection vulnerability in Squiz Matrix
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3.
network
low complexity
squiz CWE-94
8.8
2017-11-30 CVE-2017-14196 Path Traversal vulnerability in Squiz Matrix
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3.
network
low complexity
squiz CWE-22
7.5