Security in the world of the web or software is a very weak term, by which the application or CMS is only as secure or strong as its developers. In which case that would warrant community projects being more secure which again can be false.
Jommla is as a package of the shelf secure as any other (wordpress included) however like all other CMS’s if the environment is incorrect (server settings) and you have modified or installed insecure 3rd party additions you can’t expect it to remain “hacker free” and that includes updates.
The point to be made is no system is secure, regardless of its merits, in software security simply means a developer has found a way to make it difficult for another developer to crack... not impossible.
You only have to look at the specialised firms that are used to break “secure” banking and other financial or key systems when the company or its users have “locked” themselves out.