10.08.2015Vulnerability discovered.
12.08.2015Vendor contacted.
13.08.2015Vendor replies asking more details.
13.08.2015Sent details to the vendor.
14.08.2015Vendor sends details to developing team.
19.08.2015Asked vendor for status update.
19.08.2015Vendor states that some issues were fixed in 2.6.2 and rest will be fixed in 2.6.3 or 2.7.
25.08.2015Asked vendor for status update.
25.08.2015Vendor will get back to us by 15th of September because of holidays.
16.09.2015No reply from the vendor.
17.09.2015Informed vendor about public release.
17.09.2015Vendor has released version 2.6.2 fixing the file upload issue. Remaining issues promised to be fixed in next release.
24.09.2015Vendor releases version 2.6.3 to fix remaining issues?
26.09.2015Public security advisory released.