CentOS WebPanel is a web hosting control panel for CentOS-based servers that manages a narrow, focused product line. The vendor's vulnerability disclosures center on its single control-panel product and reflect input-handling and access-control issues typical of administrative interfaces deployed in production environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Centos Webpanel over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48703CRITICAL CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager ch | Sep 19, 2025 | 9.0 | 98 | YES | YES |
CVE-2020-15609CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this | Jul 28, 2020 | 9.8 | 36 | NO | NO |
CVE-2019-10893MEDIUM CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Se | Apr 18, 2019 | 4.8 | 28 | NO | YES |
CVE-2019-10261MEDIUM CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action. | Apr 3, 2019 | 4.8 | 28 | NO | YES |
CVE-2019-13386HIGH In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell | Jul 26, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-14246MEDIUM In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an at | Aug 21, 2019 | 6.5 | 20 | NO | NO |
CVE-2019-14245MEDIUM In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker a | Aug 21, 2019 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Centos Webpanel.
Media articles that mention a CVE ID that affects a product developed by Centos Webpanel — matched by CVE ID, not by vendor name.