Potentially lots for sure. Looks like the bug was known for almost two weeks before it was reported and patched and it wouldn’t have been difficult for someone to extract all the review information for any conference that had ever used the openreview platform in that time.