Anyone using the BlogEngine.net please make sure you update to the latest version Official statement: http://www.dotnetblogengine.net/post/Critical-Security-Patch-Available.aspx