Ummm, I think the idea is that he would post the vulnerabilities along with patches. Cross Site Scripting vulnerabilities aren't rocket science to fix -- and they usually aren't rocket science to find either, so it's only a matter of time before someone else finds/exploits/discloses them...
The OP has emailed the developers and now has posted a notice on their support forums. I'd say give them 1-2 weeks, and then disclose along with the patches.