Cezanne version 7 suffers from a remote SQL injection vulnerability.
4f513e27a069c861f54191d62da844a44fef875775d97ab20369bdb7cbd7f1e4
Cezanne versions 6.5.1 and 7 suffer from multiple cross site scripting vulnerabilities that require a user to be logged in (which is what you want if you are stealing cookies).
e4a896ec10b96c670a3c81498dfb55740cc5ab91c1bf38218cb47553d6ab6b2c
Cezanne versions 6.5.1 and 7 suffer from a cross site scripting vulnerability in the SleUserName parameter.
bb7a3249a474104147ff8c1167c08869b5a662f111666d8b1e543c413a1be933