Wordpress - a leading free blogging application has problems with security vulnerabilities. Certain scripts in WordPress are not properly validated thus leaving the scripts open to cross site scripting (XSS) attacks.
Holes in WordPress Blogging Program - Entire Article
Holes in WordPress Blogging Program - Entire Article