Yandex trovi.com!

Can't this issue be reported directly to Yandex?
Yandex don't even care about vulnerabilities IMO (based on my XP with them) so I bet they don't care about any of this. Sucks for Yandex users.