Geeklog versions 2.x and below are susceptible to cross site scripting vulnerabilities and various SQL injection attacks.