moderncampus CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

moderncampus vulnerability overview

Aggregates CVE and security vulnerability intelligence across all moderncampus-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk path handling and related security problems, affecting vendor surface production workloads and vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-35860 A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listing.php or rss.php. [email protected] 5.3 2.61% 2024-06-13 2024-11-21
CVE-2023-35859 A Reflected Cross-Site Scripting (XSS) vulnerability in the blog function of Modern Campus - Omni CMS 2023.1 allows a remote attacker to inject arbitrary scripts or HTML via multiple parameters. [email protected] 6.1 0.36% 2024-06-13 2025-03-17
CVE-2023-35858 XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information. [email protected] 5.3 0.73% 2024-06-13 2025-06-18
CVE-2022-40766 Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring. [email protected] 9.8 0.73% 2022-09-18 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence