OEcms 3.1 is vulnerable to reflected cross-site scripting via the mod parameter of info.php.
View the template here CVE-2018-12095.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-12095.yaml
References: