Where you should disclose your vulnerabilities. Go read RFPolicy if you want to do responsible disclosure, and go here for when all else fails. 

5 years ago
I thought this exploit was fixed sometime on the 4/5th of march yet someone here seems to have found an exploit to get 100's thousands of fans in a day or so source: How this possible? There is huge money to be made. The XSS vectors have longed been patched
