Control Webpanel is a narrowly scoped hosting control panel product that, despite a small product footprint, occupies a prominent position in the vulnerability landscape, likely reflecting its widespread deployment across web hosting infrastructure. The vendor's vulnerability disclosures span a moderate volume and cluster around a single core product, representing an important concentration point for defenders managing shared hosting or reseller environments. Weakness classes for this vendor have not been clearly characterized across its reported issues, suggesting either diverse, non-recurring flaw patterns or insufficient structural similarity to establish dominant themes. Administrators running this control panel should monitor vendor advisories closely and prioritize patching, as internet-facing administrative interfaces present high-value targets regardless of individual flaw severity; current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Control Webpanel over time
Signals from CVEs in this vendor scope (85 CVEs).
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44877CRITICAL login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the logi | Jan 5, 2023 | 9.8 | 99 | YES | YES |
CVE-2025-48703CRITICAL CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager ch | Sep 19, 2025 | 9.0 | 98 | YES | YES |
CVE-2021-45467CRITICAL In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as d | Dec 26, 2022 | 9.8 | 80 | NO | YES |
CVE-2018-18323HIGH CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI. | Oct 15, 2018 | 7.5 | 79 | NO | YES |
CVE-2021-45466CRITICAL In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the / | Dec 26, 2022 | 9.8 | 62 | NO | NO |
CVE-2022-25046CRITICAL A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request. | Jul 7, 2022 | 9.8 | 61 | NO | NO |
CVE-2021-31324CRITICAL The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution. | May 18, 2021 | 9.8 | 59 | NO | YES |
CVE-2019-13360CRITICAL In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username. | Jul 16, 2019 | 9.8 | 55 | NO | YES |
CVE-2018-18322CRITICAL CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, o | Oct 15, 2018 | 9.8 | 49 | NO | YES |
CVE-2020-10230CRITICAL CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter. | Mar 16, 2020 | 9.8 | 48 | NO | YES |
Signals from CVEs in this vendor scope (85 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Control Webpanel.
Media articles that mention a CVE ID that affects a product developed by Control Webpanel — matched by CVE ID, not by vendor name.