Moderncampus develops the Omni CMS platform for higher education content management; its limited vulnerability footprint centers on input-handling and access-control weaknesses including path traversal, cross-site scripting, SQL injection, and XML injection that are typical of web-facing CMS products. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moderncampus over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40766CRITICAL Modern Campus Omni CMS (formerly OU Campus) 10.2.4 allows login-page SQL injection via a '" OR 1 = 1 -- - , <?php' substring. | Sep 18, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-35859MEDIUM A Reflected Cross-Site Scripting (XSS) vulnerability in the blog function of Modern Campus - Omni CMS 2023.1 allows a remote attacker to inject arbitrary scripts or HTML via multip | Jun 13, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-35860MEDIUM A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listi | Jun 13, 2024 | 5.3 | 17 | NO | NO |
CVE-2023-35858MEDIUM XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1 allow a remote, unauthenticated attacker to obtain application information. | Jun 13, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moderncampus.
Media articles that mention a CVE ID that affects a product developed by Moderncampus — matched by CVE ID, not by vendor name.