Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Matrix MEDIUM 5.3
CVE-2022-32277

Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate authorization when submitting a re…

Mitigation only
Fix from $1,600 2022-09-06
Matrix CRITICAL 9.1
CVE-2019-19374

An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS…

Fix: 5.5.0.3 / 5.5.1.8+
Fix from $2,300 2019-12-11
Matrix HIGH 7.5
CVE-2019-19373

An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where …

Fix: 5.5.0.3 / 5.5.1.8+
Fix from $1,950 2019-12-11
Matrix HIGH 8.8
CVE-2017-14198

An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause…

Fix: after 5.3.6.0
Fix from $1,950 2017-11-30
Matrix HIGH 7.5
CVE-2017-14196

An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'F…

Fix: after 5.3.6.1
Fix from $1,950 2017-11-30
Matrix MEDIUM 6.1
CVE-2017-14197

An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Ma…

Fix: after 5.3.6.0
Fix from $1,600 2017-11-30
Mysource Classic MEDIUM 6.8
CVE-2006-5036

MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url p…

Fix: after 3.8
Fix from $1,600 2006-09-27
Mysource Matrix MEDIUM 6.8
CVE-2006-5037

MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src paramet…

Mitigation only
Fix from $1,600 2006-09-27
Mysource Classic MEDIUM 6.5
CVE-2006-4635

Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject a…

Fix: after 2.14.6
Fix from $1,600 2006-09-08