← Back to CVE search

CVE-2019-25737

Live Chat Unlimited

Description

Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft or forced redirects to malicious websites.

CVSS 6.1EPSS 0.211%Risk 0.62
View source
Published
2026-06-04 14:16:32
Affected versions
<= 2.8.3
Type
Web application
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N