You can read the breakdown of the XSS incident at Lemmy.world.

This won’t be an issue for Wayfarers’ Haven because we don’t actually have any custom emoji.

My main account was indeed also the admin account for the server. If I had seen that script, that would have made this server vulnerable to the attack - I may have and we just missed it out of sheer luck. That and the backup account have both been moved to alternate accounts - I’m now following security best practices by separating out admin and every day use users.

The only practical change here is that I now have to log in as a separate user to approve applications and if I feel like changing the sidebar. I’ll live. :)