BU don't use SSL/TLS so "Heartbleed" is out of the question. About Metldown and Spectre, the attacker should be able to execute the code directly on the server in order to do these attacks, so don't worry about that.
About the DDOS attacks - this is not actually a security attack and when your server is targeted by such attacks mitigating them is not easy, but the good news is that they don't last long. They are critical for hosting/service providers, it's not big deal that the forum will be down some time.