Some popular CMSs have a huge number of add-ons and try to fix every security problem as quickly as possible, without hiding. They end up with a lot of security announcements.
This seems to be the wrong way, because they distribute broken code and fix it after that. Not intentional, but that's the picture this is painting.
Are there any free CMS projects which have a strict system of code review for any given add-on? Contributing to such a project could become tiresome, but it would be worth it.
EDIT: I'm getting mixed messages on SO and other places. If you are going to ask for any good CMS, you always get the same few in the top mentioned ones. And they have one thing in common: Many modules. These CMSs define themselves by this humongous amount of add-ons, without which they weren't half as interesting.
These add-ons are "advertised" and offered on the main project's site. A repository full of code from disastrous to awesome.