the reported version of a server software is not necessarily indicative of it being vulnerable to an exploit or not, the software may have had a fix backported or had been deployed in a configuration where the vulnerability wasn’t relevant.
reporting something based on just a version string and writing a clickbait article about how the person ignored you is just shitty behavior
@ariadne KDE regularly receives reports like "Severity: High, directory listing is enabled on https://amarok.kde.org/images/", usually begging for bounties. I guess they think automated security scanners are get rich quick schemes they can use.