Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.

Snapey's avatar
Level 122

XP System broken

Its hard work staying near the top, particularly chasing @bobbybouwmann who in turn is chasing @bashy.

But now today, its all over. Possibly due to the reported XSS vulnerability, Bobby has scored over 55 best replies in one day (current profile versus the cached leaderboard)

I'm upset now, noone has been gaming my best replies and I'm now trailing by 70 when we were neck and neck previously

Somethings up @JeffreyWay

0 likes
44 replies
Snapey's avatar
Level 122

OK, so now scores are going down.....

I was on 1419 and now it says 1200 odd

@bashy now only has 470 bests

topvillas's avatar

It's almost like Ego Overflow but less whiney.

Snapey's avatar
Level 122

Looks like some form of true-up ... everyone's going down

jlrdw's avatar

What is very puzzling is how Jeffrey has not responded whatsoever.

jlrdw's avatar

I guess it's time to go back to yii framework. Yii2 is alright.

1 like
Cronix's avatar

Great, I lost 52 and am pretty sure I actually earned them all. I've been busting my ass to make it into the top 10 and have been keeping a close eye on mine for the last few weeks.

topvillas's avatar

@jlrdw JW's too busy churning out quality content or something stupid like that.

Cronix's avatar

Jeffrey said he knows who the culprit is for adding a bunch of points to other peoples xp and is fixing it. So that's probably why everything is going down. Sucks we all have to lose out on stuff we legitimately earned because of one kid. I'm pretty sure I know who it was, but hope Jeffrey announces it and bans him.

https://twitter.com/bobbybouwmann/status/991678176467324928

Cronix's avatar

Not sure why they'd go down unless the thread was removed? Not sure.

Possibly just resetting them to where they all were before it happened?

bobbybouwmann's avatar

Yeah I contacted Jeffrey about it.. Wasn't happy either! A lot of energy has been put into this!

1 like
bashy's avatar

@Cronix Did you answer one of his topics correctly then? I believe it was only from marking it correct multiple times.

Cronix's avatar

@bashy I don't recall specifically getting a best reply award for answering one of rin4ik posts.

1 like
JeffreyWay's avatar

Fake accounts were created that disproportionately liked the replies of certain accounts here.

I deleted those accounts, and am adjusting all stats to be what they should have been.

2 likes
bobbybouwmann's avatar

I still see some incorrect scores, but you're probably busy with it!

bobbybouwmann's avatar

@rin4ik Yeah, Jeffrey is fixing stuff now! But instead of breaking all the scores you should have contacted Jeffrey!!

1 like
JeffreyWay's avatar

The best reply award count is now correct for everyone. That number is based on all threads that currently have your reply as the best one.

Before, we wouldn’t decrement your award count if a thread author changed their mind about the best reply. Now we do.

bobbybouwmann's avatar

@JeffreyWay What about the points? I was about 5k points behind bashy, but now there is a huge gap again... It's not about my points or any leaderboard status, but there is still something off here!

jlrdw's avatar

Thank you @JeffreyWay for responding, is the hack also repaired? I won't really go to yii, Yuk, I like laravel.

1 like
jlrdw's avatar

We were like sad puppies, but now Jeffrey has come along, pet us and gave us treat. We are happy again. That is until feeding time.

@Cronix

What about the "best reply" awards?

Don't worry you still have more than me.

1 like
rin4ik's avatar

@Cronix what about this

Fake accounts were created that disproportionately liked the replies of certain accounts here.

and in one thread should be only one best reply. if I tomorrow be in 10 place with multiple best replies what you can do ? nothing. now it's fixed

Cronix's avatar

Are you asking us to thank you for exploiting these various things and messing with the forum instead of doing the responsible thing and reporting them to Jeffrey?

2 likes
jlrdw's avatar

But what's scary is other sites may have the exploit where a persons money is involved.

People I have begged folks to stop using the latest thing for a web app. Enterprise and Governments usually lag 9 months to a year to let bugs be worked out. There is a reason they do so.

Play site, ok, real site, no.

Cronix's avatar

@jlrdw This isn't a bug in Laravel. The bug was in the forum. Read Jeffreys post above about "best reply award count"

Next

Please or to participate in this conversation.