> Of course, if the rails community responds quite rapidly, the return-on-effort for the black hats drops substantially. (hint hint)
Well, not quite. In security there's a fundamental imbalance between attackers and defenders: a defender needs to find every bug, where an attacker only needs to find one. At the end of the day, if it's a platform that's worth attacking, attackers will always have the upper hand. This is why finding and fixing individual bugs is not nearly as effective as eliminating whole classes of bugs; of course, it's much cheaper to do.
Rails has been pretty good on the whole, in terms of security. Given the size and wide distribution of the platform, it's held up impressively well. Of course, the last couple bugs have marred that a bit, and there are definitely places where Rails apps have traditionally failed badly (e.g. mass assignment).