Bluepage CMS versions 2.5 and below suffer from cross site scripting and session fixation vulnerabilities.