However this is because web programming as a whole is a crock from top to bottom. PHP doesn't really add or subtract from that other than lowering the barrier to entry with respect to compromising your server through stupid architectural or coding decisions.
If we wrote our web pages in C, it's be just as bad. Rails has a terrible history of vulnerabilities. Many times I've seen injection attacks in audited Java and C# applications.
Everything can be a turd in the wrong hands.