Security fixes target the latest released minor version and main.
Do not open a public issue for an unpatched vulnerability. Email supportramsandesh@gmail.com with the affected component, reproduction details, realistic impact, and any suggested mitigation. Avoid including real student or staff data.
The maintainers will validate the report, coordinate a fix, and credit reporters when requested and appropriate. Never test against systems you do not own or have explicit permission to assess.