CVE-2018-12095: Oecms Project Oecms

Medium severity, CVSS 5.4. EPSS: 5.6% chance of exploitation in the next 30 days.

A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.

Affected products

Published 2018-06-11. Last modified 2026-06-17.