We only support the latest release of Codename One and don't maintain backports.
IMPORTANT there is no bounty for security issues. We're an OSS project and don't have a budget. The best you can expect is a thank you and a mention in our blog.
You can use the website chat in https://www.codenameone.com/ to report a vulnerability.