xt:Commerce versions 3.04 and below suffer from cross site scripting and session fixation vulnerabilities.