Drupal, from my experience, seems the most dedicated to being secure. They have a pretty good reputation as far as open source software goes in that respect.
I just wanted to highlight what on!SPOT said, oftentimes it's not the actual software but installed third party scripts that are hacked. I recommend using as few as possible and doing your best to keep up with new releases. While software is exploited, more often than not it comes down to a script that went upgrade-less or a bad addon.