CVE-2019-19908: Ciprianmp Phpmychat-Plus

Medium severity, CVSS 6.1. EPSS: 21.2% chance of exploitation in the next 30 days.

phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.php is vulnerable.

Affected products

Published 2019-12-20. Last modified 2026-06-17.