I've been having a mess around in the groups section and found the following problems:
HTML code is allowed in group names, description, tags, new topics etc and can be abused to mess up the page.
Viewing the groups by "Most Topics" displays them all with no group name in the URL.
when creating a new topic if you leave the "attach a video" as "- your videos -" or "- you favorite videos -" then the new topic will have a broken video attached to it.
When editing a group you forgot the </a> at the top where "Edit Group: {name}" is. This makes the whole form a link in opera and thus wont allow you to do changes.
when creating a group if you use a name for the "unique group name URL" that is already taken it will give you the error "Please provide unique part of url." This error should be changed so the user knows that it already exists and should choose something else instead.
in the Admin area in "All Groups" clicking on any of the numbers listed under "Video, Member, Topics" gives an error "Fatal error: Call to a member function on a non-object in......"
Bookmarks