Meta · Facebook · CVE-2025-51398
**Name of the Vulnerable Software and Affected Versions**
Live Helper Chat version 4.60
**Description**
A stored cross-site scripting (XSS) vulnerability exists in the Facebook registration page. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the `Name` parameter.
**Recommendations**
Update to a newer version that contains a fix for this issue. As a temporary workaround, consider sanitizing user input for the `Name` parameter on the Facebook registration page.