Persistent XSS
In Blogtags (reported, but not fixed)
In Grouplocation Tag and Group Website field (reported, but not fixed)
Reflective XSS
On Profile not found page
(already fixed)
Edit:
Workarround not acceptable works with other attack vector.
Same on Group not found page and so on.
Opera…
Continue