CVE-2019-19908: Ciprianmp Phpmychat-Plus
Medium severity, CVSS 6.1. EPSS: 21.2% chance of exploitation in the next 30 days.
phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.
Affected products
- Ciprianmp Phpmychat-Plus: version 1.98 only
Published 2019-12-20. Last modified 2026-06-17.