Thank you for find these XSS vulnerabilities. They have been patched in the 1.0.3 version, released earlier this evening.
Mail converted by mhonarc 2.6.15 This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.