Earlier quoted context omitted.
I think the timeline is the more damaging part too. Not only was their design woefully inadequate, they don't seem to care.
The problem is they probably don’t have full time developers. They probably built the app once years ago via a dev shop and then never updated it again. The talent moved on and updating it is expensive now.
I have no idea if the back end was also replaced then or if the vulnerabilities were present in the previous version as well.