This document describes how security incidents are handled since Flyspray 0.9.9.
You can read a list of known security problems on Flsypray's Secunia.com page
PHP security holes, where the only real solution is to upgrade your PHP version to be protected.
Also, There are a few third party flyspray integrations that we are aware of :
Please do not contact us about vulnerabilities in that products, unless the problem is present in officially supported Flyspray releases available in either the download section or in the active branches of our SVN repository.
We have no control of the code included in that tools.