Phpmychat-Plus
Ciprianmp · 3 CVEs
CVE-2020-37151
HIGH
phpMyChat Plus 1.98 'deluser.php' SQL Injection
Feb 5, 2026
CVE-2020-9265
HIGH
phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demo…
Feb 18, 2020
CVE-2019-19908
MEDIUM
phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, th…
Dec 20, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-37151 | phpMyChat Plus 1.98 'deluser.php' SQL Injection | HIGH | 0.45% | Feb 5, 2026 |
| CVE-2020-9265 | phpMyChat-Plus 1.98 is vulnerable to multiple SQL injections against the deluser.php Delete User functionality, as demonstrated by pmc_username. | HIGH | 1.46% | Feb 18, 2020 |
| CVE-2019-19908 | phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the pmc_username parameter to pass_reset.p… | MEDIUM | 21.23% | Dec 20, 2019 |
Showing 1 to 3 of 3 CVEs