PHParanoid before 0.4 does not properly restrict access to the members area by unauthenticated users, which has unknown impact and remote attack vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/40516
http://sourceforge.net/project/shownotes.php?release_id=575358