txtBB versions 1.0 RC3 and below suffer from a HTML/Javascript injection vulnerability that allows for privilege escalation.