ConPresso CMS versions 4.0.4a and prior suffer from multiple cross site scripting and SQL injection flaws.