I know what should make a "serious bug reporter" but a "serious webmaster" should allow the bug reporters to contact him privately.
When I click on "contact", I've 3 choices :
- Mailing list (not private)
- IRC (nobody!)
- Forums (here I am)
I haven't explain the vulnerability, and I'm waiting for ...