I've used opensim vulnerablities in 15 different opensim grids and the owners dont even know. Everything from spoofing UUID'S to stealing session tokens. Some grid owners dont even keep their grids safe. :]
Recently, even major U.S. government systems and large services like Gyazo have dealt with serious security breaches. Those are organizations with far more money, staff, and security resources than most OpenSim grids. So bragging that you found vulnerabilities in small grids isn’t really the flex you think it is. Finding a weakness is easy compared with responsibly reporting it and helping get it fixed.