I's kind of incredible how common this specific kind of vulnerability is. I have to assume the developers of these systems just hope that no one will notice?
Instead, they are interested in delivering buttons, fields, and streamlined workflows. Technical debt and library upgrades? Os upgrades? Forget about it. They need to deliver value back to the business in terms of faster business processes.
Only when the business is hacked or they fail compliance does the business leadership start to care.
Blaming the people with the hands on the tools is not fair when the business will not give the resources to do their work properly.
[1] I'm thinking in particular of Ars Digita's second system effect Java replacement for their original Tcl environment. It tried to turn everything into late 1990s Java buzzwords and was completely opaque, as well as being comically inefficient.