Security · Hall of Fame

Thanks for keeping us honest.

Researchers who reported valid, in-scope issues under our disclosure policy. Ranked by report date.

01
Japz Divino
Stored XSS in the GHOSTFACE post feature — unsanitized post content could execute script against other viewers.
REPORTED 2026-07-19 · STATUS: FIXED
High
02
DanIzDev
Direct access to the admin login endpoint (/admin/login) — a predictable, publicly reachable admin surface. Hardened with an authentication gate at the edge.
REPORTED 2026-08-11 · STATUS: FIXED
Low
Found something? Report it and your name goes here next.