The reasons are a combination of things. The language tries to volunteer to do too much for you by default. The environment it is run in tries to do too much for you by default. The past defaults were even worse. A lot of available software in PHP was written with no attention to security, and it still shows. And it has attracted a community that fails to recognize these things as problems.
Yes, in theory you can write PHP and make it as secure as anything else. In practice it doesn't happen that way. And until PHP developers stop patting themselves on the back and assuring themselves that they are really OK, they will continue to have big problems.