PHPBB (a popular forum software) has been stuck at version 2.x for a long time now. It has been plagued with many security issues, a long with poor W3C standards.
Version 3 (formally 2.2) which has been running years late is now almost ready for beta testing. I wonder if this new version will bring phpbb up to standards.
I've just had a look at PunBB. Was just reading their release notes and it seems like they're having their fair share of security holes too.
Also I don't like how they "secure" the software. i.e one user registration per ip address per hour.
Bleh... it sucks. I've been recommending PunBB to people for a couple of months now. It's light-weight, uses web standards, and is generally a great deal better than the behemoth de facto forum software out there (phpBB, Invision whatever-it's-called, etc.)