The old version of the Lexicon (the one being referred to here) relied on the server admin knowing what to blacklist and being willing to do it.
Lesson learned - the new one (OmniTools 3.0+) is whitelist by default and will generate a list that it feels is appropriate if not provided one. This new list can then be modified should the server admin choose to do so.
Strictly speaking, none of the issues with the Lexicon are outright exploits, as the ability to disable the conversion has always existed, it's a question of willpower.