I'd like to point you to https://statuscode.ch/2015/09/ownCloud-security-development-... and make you aware of https://seacloud.cc/group/3/wiki/security-records.md and you should probably consider who reported the last critical vulnerability.
Only because a project is serious about actually publishing vulnerability data does not make it necessarily more insecure (or secure).