

I refuse to browse/watch shorts directly; probably because I know I’ll get sucked in to it for several hours, but I also know there’s very little useful/valuable info there. I’ll will however occasionally watch other typically gaming YouTubers, reacting to collections of shorts.
Without authentication; it’s possible to randomly generate UUIDs and use them to retrieve media from a jellyfin server. That’s about the only actually concerning issue on that list, and it’s incredibly minor IMO.
With authentication, users (ie, the people you have trusted to access your server) can potentially attack each other, by changing each others settings and viewing each other’s watch history/favorites/etc.
That’s it. These issues aren’t even worth talking about for 99.9% of jellyfin users.
Should they be fixed? Sure, eventually. But these issure aren’t cause to yell about how insecure jellyfin is in every single conversation, and to go trying to scare everyone off of hosting it publicly. Stop spreading FUD.