Control-Webpanel / Webpanel
85 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-48703 KEV | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total paramete… | CRITICAL | 9.0 | Sep 19, 2025 |
| CVE-2023-42123 | Control Web Panel mysql_manager Command Injection Remote Code Execution Vulnerability | HIGH | 8.8 | May 3, 2024 |
| CVE-2023-42122 | Control Web Panel wloggui Command Injection Local Privilege Escalation Vulnerability | HIGH | 7.8 | May 3, 2024 |
| CVE-2023-42121 | Control Web Panel Missing Authentication Remote Code Execution Vulnerability | CRITICAL | 9.8 | May 3, 2024 |
| CVE-2023-42120 | Control Web Panel dns_zone_editor Command Injection Remote Code Execution Vulnerability | HIGH | 8.8 | May 3, 2024 |
| CVE-2022-44877 KEV | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metac… | CRITICAL | 9.8 | Jan 5, 2023 |
| CVE-2021-45467 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an ar… | CRITICAL | 9.8 | Dec 26, 2022 |
| CVE-2021-45466 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_ke… | CRITICAL | 9.8 | Dec 26, 2022 |
| CVE-2022-25048 | Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user. | HIGH | 8.8 | Jul 7, 2022 |
| CVE-2022-25047 | The password reset token in CWP v0.9.8.1126 is generated using known or predictable values. | MEDIUM | 5.9 | Jul 7, 2022 |
| CVE-2022-25046 | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request. | CRITICAL | 9.8 | Jul 7, 2022 |
| CVE-2021-31316 | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter. | CRITICAL | 9.8 | May 18, 2021 |
| CVE-2021-31324 | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution. | CRITICAL | 9.8 | May 18, 2021 |
| CVE-2020-15628 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15627 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15626 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15625 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15624 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15623 | This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not requ… | CRITICAL | 9.8 | Jul 28, 2020 |
| CVE-2020-15622 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15621 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15620 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15619 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15618 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
| CVE-2020-15617 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is… | HIGH | 7.5 | Jul 28, 2020 |
Showing 1 to 25 of 85 CVEs