If you discover a security vulnerability in the SE Site project, please report it privately to the SPbSU System Programming Department administration.
Do NOT report security vulnerabilities via public GitHub issues.
Only the latest release (tagged vYYYY.MM.DD on the current branch) receives
security fixes.
Vulnerabilities are fixed via a dedicated security PR, reviewed, and released as part of the next scheduled release. Critical vulnerabilities may trigger an out-of-cycle release.
We thank security researchers who report vulnerabilities responsibly.