[This was originally disclosed on the SourceForge bug tracker. VulnDB 15754, 15755, & 15756]
in 0.7.4:
The blog entry title field seems prone to cross site scripting (XSS) attacks.
The blog/comment body text seems prone to XSS as well.
In the index.php script, the postid variable seems prone to SQL injection attacks.