Report a vulnerability
Last reviewed: 23 August 2026
This is the central security contact for Zilaro, publicly distributed Medienmacher plugins and medienmacher.biz.
Report confidentially
First send a short message to tom@medienmacher.biz. Include the affected product, version, observed impact and a safe return channel. Receipt is normally acknowledged within three Austrian business days.
Do not send by ordinary email
- real customer, health, payment or authentication data,
- active credentials or passwords,
- complete exploit payloads or malicious files.
If such material is essential, a protected transfer channel will be coordinated after the initial report.
Useful details
- product, version and affected URL or component,
- reproduction steps using synthetic test data,
- expected and actual behaviour,
- potential impact and known active exploitation,
- protective measures already taken.
Coordinated disclosure
Reports are risk-prioritised, checked for reproducibility and recorded without unnecessary personal or harmful content. Please disclose technical details only after a coordinated fix or an agreed date. Statutory reporting duties remain unaffected.
Scope
Current supported versions of public Medienmacher software and medienmacher.biz are in scope. Social engineering, physical attacks, denial-of-service or automated load testing, and access to third-party data are prohibited.