CVE-2026-3946

Publication date

2026-03-11 15:02:08

Family

VulDB

State

PUBLISHED

Description

A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-ask. Performing a manipulation of the argument askcontent results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.