control-webpanel records
85 published records for vendor control-webpanel.
Researcher profile
- Entered KEV
- 2 · 2.4%
- Weaponized
- 2 · 2.4%
- Pre-auth RCE
- 32
- With a fix record
- 0%
- Median publish → KEV
- 29 days
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')33
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')14
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-639 Authorization Bypass Through User-Controlled Key5
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
85 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2022-44877Weaponized | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commacontrol-webpanel · webpanel · CWE-78 | Critical9.8 | KEV | 100.0% | Jan 5, 2023 |
96Now | CVE-2025-48703Weaponized | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in tcontrol-webpanel · webpanel · CWE-78 | Critical9.0 | KEV | 99.7% | Sep 19, 2025 |
60This week | CVE-2021-45467Proof of concept | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.phcontrol-webpanel · webpanel · CWE-862 | Critical9.8 | — | 70.7% | Dec 26, 2022 |
56Plan | CVE-2022-25046No exploit | A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.control-webpanel · webpanel · CWE-22 | Critical9.8 | — | 57.4% | Jul 7, 2022 |
56Plan | CVE-2021-45466No exploit | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to acontrol-webpanel · webpanel · CWE-863 | Critical9.8 | — | 55.3% | Dec 26, 2022 |
51Plan | CVE-2018-18323Proof of concept | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=filcontrol-webpanel · webpanel · CWE-22 | High7.5 | — | 70.7% | Oct 15, 2018 |
49Plan | CVE-2021-31324Proof of concept | The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Executioncontrol-webpanel · webpanel · CWE-78 | Critical9.8 | — | 34.6% | May 18, 2021 |
46Plan | CVE-2019-13360Proof of concept | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging kcontrol-webpanel · webpanel · CWE-639 | Critical9.8 | — | 24.5% | Jul 16, 2019 |
44Plan | CVE-2020-10230Proof of concept | CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php tcontrol-webpanel · webpanel · CWE-89 | Critical9.8 | — | 15.8% | Mar 16, 2020 |
44Plan | CVE-2018-18322Proof of concept | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_startcontrol-webpanel · webpanel · CWE-78 | Critical9.8 | — | 15.1% | Oct 15, 2018 |
43Plan | CVE-2021-31316Proof of concept | The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.control-webpanel · webpanel · CWE-89 | Critical9.8 | — | 13.3% | May 18, 2021 |
42Plan | CVE-2020-15429No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.4% | Jul 28, 2020 |
42Plan | CVE-2020-15435No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.4% | Jul 28, 2020 |
42Plan | CVE-2020-15612No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.4% | Jul 28, 2020 |
42Plan | CVE-2020-15434No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.4% | Jul 28, 2020 |
42Plan | CVE-2020-15422No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.4% | Jul 28, 2020 |
42Plan | CVE-2020-15623No exploit | This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-749 | Critical9.8 | — | 8.3% | Jul 28, 2020 |
41Plan | CVE-2022-25048No exploit | Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.control-webpanel · webpanel · CWE-78 | High8.8 | — | 19.8% | Jul 7, 2022 |
41Plan | CVE-2020-15611No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.3% | Jul 28, 2020 |
41Plan | CVE-2020-15420No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.1% | Jul 28, 2020 |
41Plan | CVE-2020-15425No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.1% | Jul 28, 2020 |
41Plan | CVE-2020-15428No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.1% | Jul 28, 2020 |
41Plan | CVE-2020-15430No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.1% | Jul 28, 2020 |
41Plan | CVE-2020-15431No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.1% | Jul 28, 2020 |
41Plan | CVE-2020-15426No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.control-webpanel · webpanel · CWE-78 | Critical9.8 | — | 8.1% | Jul 28, 2020 |
- CVE-2022-4487799Now
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS comma
CriticalCVSS 9.8KEVWeaponizedEPSS 100%control-webpanel · webpanelJan 5, 2023
- CVE-2025-4870396Now
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in t
CriticalCVSS 9.0KEVWeaponizedEPSS 100%control-webpanel · webpanelSep 19, 2025
- CVE-2021-4546760This week
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.ph
CriticalCVSS 9.8Proof of conceptEPSS 71%control-webpanel · webpanelDec 26, 2022
- CVE-2022-2504656Plan
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
CriticalCVSS 9.8No exploitEPSS 57%control-webpanel · webpanelJul 7, 2022
- CVE-2021-4546656Plan
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to a
CriticalCVSS 9.8No exploitEPSS 55%control-webpanel · webpanelDec 26, 2022
- CVE-2018-1832351Plan
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=fil
HighCVSS 7.5Proof of conceptEPSS 71%control-webpanel · webpanelOct 15, 2018
- CVE-2021-3132449Plan
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution
CriticalCVSS 9.8Proof of conceptEPSS 35%control-webpanel · webpanelMay 18, 2021
- CVE-2019-1336046Plan
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging k
CriticalCVSS 9.8Proof of conceptEPSS 24%control-webpanel · webpanelJul 16, 2019
- CVE-2020-1023044Plan
CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php t
CriticalCVSS 9.8Proof of conceptEPSS 16%control-webpanel · webpanelMar 16, 2020
- CVE-2018-1832244Plan
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start
CriticalCVSS 9.8Proof of conceptEPSS 15%control-webpanel · webpanelOct 15, 2018
- CVE-2021-3131643Plan
The unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.
CriticalCVSS 9.8Proof of conceptEPSS 13%control-webpanel · webpanelMay 18, 2021
- CVE-2020-1542942Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1543542Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1561242Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1543442Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1542242Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1562342Plan
This vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2022-2504841Plan
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
HighCVSS 8.8No exploitEPSS 20%control-webpanel · webpanelJul 7, 2022
- CVE-2020-1561141Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1542041Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-el7-0.9.8.891.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1542541Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1542841Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1543041Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1543141Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020
- CVE-2020-1542641Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.
CriticalCVSS 9.8No exploitEPSS 8%control-webpanel · webpanelJul 28, 2020