Leap CMS version 0.1.4 suffers from cross site scripting, shell upload, and remote SQL injection vulnerabilities.