Carbon Communities Forum versions 2.4 and below suffer from SQL injection and cross site scripting vulnerabilities.