Only the latest stable version is actively supported with critical bug fixed and security issues.
Vulnerabilities can be reported to the maintainers email address (see git logs).
All the security issues will be analyzed, and a reply will be given in two working days. Once the issue is accepted it will be fixed in the current development branch and for the latest version. A new version would be released.