With regards to Joomla, it really is terrible when it comes to security. Versions 1.5-2.5 have major vulnerabilities that allows anyone to create an admin user unless you disable account registration. Popular plugins like TinyMCE allowed unauthorised users to upload arbitrary files with a specially crafted request.
There are also plenty of bots that scan for vulnerable Joomla installs as they do with Wordpress.