Well, I'm rather comfortable with his kind of project, I've been some months coding in PHP and so far I'm able to create a forum, and should be SQLi, XSS, RFI and LFI Safe-Proof.
Although I agree with factionwars and I believe we should start with some already known CMS so people can get used to it, the way of coding, the variables, the protection system, everything.
In fact, we could simply pick up in some CMS and modify and add some utility's, for instance we could add some more tags, more search filters, we could even implement Ajax and XHTMLPreRequest (the function to update a field without reloading the whole page).