Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Control Webpanel

First CVE: Jan 22, 2018Active for: 9 yearsTotal CVEs: 170

Control Webpanel is a narrowly scoped hosting control panel product that, despite a small product footprint, occupies a prominent position in the vulnerability landscape, likely reflecting its widespread deployment across web hosting infrastructure. The vendor's vulnerability disclosures span a moderate volume and cluster around a single core product, representing an important concentration point for defenders managing shared hosting or reseller environments. Weakness classes for this vendor have not been clearly characterized across its reported issues, suggesting either diverse, non-recurring flaw patterns or insufficient structural similarity to establish dominant themes. Administrators running this control panel should monitor vendor advisories closely and prioritize patching, as internet-facing administrative interfaces present high-value targets regardless of individual flaw severity; current severity, exploitation activity, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
85
Total CVEs
More Total CVEs than 99% of tracked vendors
10.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
2.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Control Webpanel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2018
8 years ago
Most Recent CVE
Sep 19, 2025
308 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (85 CVEs).

85 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-44877CRITICAL
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the logi
Jan 5, 20239.899YESYES
CVE-2025-48703CRITICAL
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager ch
Sep 19, 20259.098YESYES
CVE-2021-45467CRITICAL
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as d
Dec 26, 20229.880NOYES
CVE-2018-18323HIGH
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.
Oct 15, 20187.579NOYES
CVE-2021-45466CRITICAL
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /
Dec 26, 20229.862NONO
CVE-2022-25046CRITICAL
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
Jul 7, 20229.861NONO
CVE-2021-31324CRITICAL
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
May 18, 20219.859NOYES
CVE-2019-13360CRITICAL
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.
Jul 16, 20199.855NOYES
CVE-2018-18322CRITICAL
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, o
Oct 15, 20189.849NOYES
CVE-2020-10230CRITICAL
CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.
Mar 16, 20209.848NOYES
View all 85 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products85 CVEs
29%
27%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (2.4%)
Network83 (97.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low82 (96.5%)
High3 (3.5%)
Unknown0 (0.0%)
User Interaction
None72 (84.7%)
Unknown0 (0.0%)
Required13 (15.3%)
Privileges Required
Low21 (24.7%)
High2 (2.4%)
None62 (72.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (85 CVEs).

CISA KEV
2 CVEs
2.4% of CVEs· 99th percentile
Metasploit
1 CVE
1.2% of CVEs· 97th percentile
Nuclei
6 CVEs
7.1% of CVEs· 96th percentile
ExploitDB
14 CVEs
16.5% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Control Webpanel.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Control Webpanel — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Control Webpanel's Products

View all 2 CNAs →

Top CWEs