SME Server does not come with the latest and greatest versions of many popular applications.
SME Server 7.x is based on Centos 4.x which in turn is based on RedHat Enterprise Linux 4.x. Since the development team is limited in person and time, all work is done in spare time, we do not have the time to implement such big changes and cope with the maintenance of such work.
Is xxx on SME Server still safe to run?
Yes, because security fixes and bug fixes are backported to the 4.x releases and they are propagated to the users as updates, for more information have a look at http://www.redhat.com/security/updates/backporting.
Can I install a later version of xxx
Yes, but you are then responsible for updates and possible conflicts with updates
For example see this page for PHP#PHP_5 PHP updates and warnings