Please do not report security vulnerabilities through public GitHub issues or pull requests — that discloses the problem before a fix can ship.
Instead, use GitHub's private vulnerability reporting: go to the repository's Security tab → Report a vulnerability. We'll follow up there, ship a fix, and credit you in the release notes unless you prefer otherwise.
Crowi 2.x (the current alpha line) receives security fixes. The legacy 1.x line is unmaintained.