Is there an e-mail address I can respond to apart from security@ if I find more flaws? (Or anyone else reading this)

This is frustrating... try to e-mail security@punbb.org and find that it bounces:

This is an automatically generated Delivery Status Notification

Delivery to the following recipient failed permanently:

    security@punbb.org

  ----- Original message -----

Received: by 10.35.107.20 with SMTP id j20mr7307212pym;
       Mon, 24 Jul 2006 03:21:27 -0700 (PDT)
Received: by 10.35.67.13 with HTTP; Mon, 24 Jul 2006 03:21:27 -0700 (PDT)

...

If it was a serious hole, I'd probably either sit on it or e-mail someone directly, but here goes:

-----------------------------------------------
Message removed.
-----------------------------------------------