Every language has its troubled history, but PHP is especially famous for security vulnerabilities by either beginners or intuitive API design.
It might have something to do with the fact that PHP is still taught in a lot of web dev classes (though NodeJS has taken its crown) and that Go is relatively unknown for beginning programmers. Python generally just runs on your own machine because it's not as optimized for being a web language like PHP has been.