They are open. Can you not submit an issue?
Also, can you please list the obvious security vulnerabilities here?