CVE-2017-14198: Squiz Matrix
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.
Affected products
- Squiz Matrix: up to and including 5.3.6.0; version 5.4.0.0 only; version 5.4.0.1 only; version 5.4.0.2 only; version 5.4.0.3 only; version 5.4.1.0 only; …
Published 2017-11-30. Last modified 2026-06-17.