I'm very tempted to switch to XenForo, but I cannot find any information about its policy and procedures when it comes to security vulnerabilities.
Do you release patches for some of the previous releases with backported fixes, or is the only option to update to the latest version if a security...