Classic CGI is not the best performing interface, yes. But there's a big difference in launching a complete interpreter for every request, and running a small purpose-built native program. And remember that people did manage the former 20 years ago, sites like Slashdot were running CGI Perl scripts back then.
I'm not sure about the "chock full of potential security issues". You have to be careful with trusting environment variables as the Bash guys learned, but I don't know what else there is that is specific to CGI.