Have you already fixed these issues in some version?
http://www.htbridge.ch/advisory/xss_in_a_really_simple_chat_arsc.html
http://www.htbridge.ch/advisory/multiple_sql_injections_in_a_really_simple_chat_arsc.html
If I am correct there is no CVE-identifier for these yet, because htbridge does not know how to do security advisories well. Did you already get notified about these vulnerabilities?
CVE-identifiers requested: http://www.openwall.com/lists/oss-security/2011/06/02/1