Allow me to refer you to:
Vbulletin : Security vulnerabilities
This is why you don't want to stay with a product that has a terrible development team.
Years ago, Jelsoft sold out to a crew of ass clowns that can't code for shit, so patching the older software is a lot tougher to do without the developers that coded it because the new crew are inept.
Also, as holes are patched, it increases the likelihood of opening new ones, especially when some patches affect others.
NOT patching the holes means leaving your information vulnerable to anyone with a basic understanding of software exploits, and I'm sure CK doesn't want people having their passwords, e-mail addresses, and PM's compromised on his watch.
Grow up and learn a little something about what you're bitching about.