Mostly, I think, the problem is SQL injection, and raw SQL is a great place for people to forget to escape their strings.
ORMs let anyone make CRUD apps without needing to worry about that sort of thing. Also helps prevent issues from slipping through on larger teams with more junior developers. Or, frankly, even “senior” developers that don’t really understand web security.