Anyone know if an exploit can launch from clicking on the notifications or messages at the upper right box with your username? I clicked to open a notification (notif) from someone I did not recognize. The notification did not load even after several attempts so I didn't even have the opportunity to click on any links in the notification, if there were any. After I did that however, I could not navigate to other parts of the site like my finances and profile. It would say that I'm not logged in, but when I return to the homepage, it says that I'm logged in.
Certainly sets off a few warning flags. I'd not keep too much in your account. Although i'd be very surprised if the site enabled notifications allowed script executions but at the same time, it's not intangible.