For me, one of the primary benefits of ORMs is that they can parameterize requests which then prevents SQL injection attacks.
Passing raw SQL to the database needs very careful attention to the dynamic parts, and it's too easy for user-generated data to be included.
Yes, it's possible to pass user generated text through a sanitizer but now you just have an arms race between the sanitizer and "clever" users.