Report privately through this repository's GitHub "Report a vulnerability" form (Security tab → Advisories), never as a public issue.
Scope: this repository (opensoft/openXdox-code), the code leg of the
openXdox project.
Expected acknowledgement within 7 days.