Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-25262

17
FAUCET Score

CVE-2019-25262 is a Cross-Site Scripting (XSS) vulnerability in the Chat Message Handler component of elinicksic Razgover, specifically in the Chattify/send.php file, affecting versions up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This vulnerability, caused by improper handling of the 'msg' argument, allows remote attackers to inject malicious scripts. Rated with a CVSS score of 3.5 (LOW), it requires user interaction and low privileges, with a potential impact of low integrity and no confidentiality or availability compromise. Although a patch (995dd89d0e3ec5522966724be23a5d58ca1bdac3) exists, the affected product is no longer supported, and there is no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
ElinicksicRazgover
db37dfc5c82f023a40f2f7834ded6633fb2b5262CNA affected

CVSS Data

CVSS version used by this source: 4.0

5.1MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 29th percentile among its peer group of 406 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / elinicksic/Razgover/commit/995dd89d0e3ec5522966724be23a5d58ca1bdac3
vuldb.com
vuldb.com