XCMS versions 1.82 and below suffer from local file inclusion and code execution via upload vulnerabilities.