Oh wow, unprotected admin tools and an XSS vulnerability on their main homepage that is used for customer logins. That's pretty bad.
I've encountered this problem frequently when interacting with various organizations. The pervasive availability of bug-tracking systems and/or bug-reporting email addresses makes the absence of one quite conspicuous.