BLOG:CMS versions 4.x prior to 4.2.0 suffer from a cross site scripting vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75709/PT-2009-14.txt
Source: https://packetstormsecurity.com/files/75709/BLOG-CMS-Cross-Site-Scripting.html

