Community Gallery 2.0 Cross Site Scripting

Community Gallery version 2.0 prior to 12/10/2014 suffers from a cross site scripting vulnerability.