While I don't expect yiff.tube to be a primary target for attacks and leaks, I can't believe they're just sending passwords in e-mails. A site shouldn't even have it stored in a decryptable form, let alone sending it in plain text.
I'm honestly surprised XSS and SQL Injection don't work on the site, though webdesign was probably done by someone less retarded than whoever managed the servers.