CVE-2026-3946
Published
CVSS v3
3.5
LOW
CVSS v2
4
MEDIUM
Affected
2
PROJECTS
Description
A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-ask. Performing a manipulation of the argument askcontent results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.