Most are WordPress, and it's not like WordPress has had a smooth development history... It's one of the most-exploited entry points into a server. That's why anyone running a server for long enough will see tons of hits to their access logs looking to /wp-admin and other WP-specific URIs.