SME Server does not come with the latest and greatest versions of many popular applications.
SME Server 10.x is based on Centos 7.x which in turn is based on RedHat Enterprise Linux 7.x. Since the development team is limited in persons and time, all work is volunteered, we do not have the time to rapidly implement big changes and cope with the resulting maintenance.
Is xxx on SME Server still safe to run?
Yes, because security fixes and bug fixes are backported to the 4.x releases and they are propagated to the users as updates, for more information have a look at http://www.redhat.com/security/updates/backporting.
Can I install a later version of xxx
Yes, but you are then responsible for updates and possible conflicts with updates
For example see this page for PHP#PHP_5 PHP updates and warnings