cpCommerce version 1.1.0 suffers from cross site scripting, SQL injection, and local file inclusion vulnerabilities.