vBulletin is pretty solid and I don't have much fear of my site being hacked. What I do fear is installing "third party" plugins that could leave my site wide open for attack.
For example, I've seen allot of people request a hack similar to vBulletin's bug tracker. The answer was
vBug Tracker that has
a known security hole since April of 2006 and it has yet to be updated by the author.
It is third party plugins that make vBulletin vulnerable and as a rule of thumb I always question the reputation of the developer.