Webpanel
Vendor:
First CVE: Jan 22, 2018 · Active for 8 years
85
Total CVEs
More Total CVEs than 99% of tracked products
10.6
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
2.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Webpanel over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2018
8 years ago
Most Recent CVE
Sep 19, 2025
308 days ago
CVE Severity & Scoring
Webpanel85 CVEs
29%
27%
44%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (2.4%)
Network83 (97.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low82 (96.5%)
High3 (3.5%)
Unknown0 (0.0%)
User Interaction
None72 (84.7%)
Unknown0 (0.0%)
Required13 (15.3%)
Privileges Required
Low21 (24.7%)
High2 (2.4%)
None62 (72.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (85 CVEs).
85 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44877CRITICAL login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the logi | Jan 5, 2023 | 9.8 | 99 | YES | YES |
CVE-2025-48703CRITICAL CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager ch | Sep 19, 2025 | 9.0 | 98 | YES | YES |
CVE-2021-45467CRITICAL In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as d | Dec 26, 2022 | 9.8 | 80 | NO | YES |
CVE-2018-18323HIGH CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI. | Oct 15, 2018 | 7.5 | 79 | NO | YES |
CVE-2021-45466CRITICAL In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the / | Dec 26, 2022 | 9.8 | 62 | NO | NO |
CVE-2022-25046CRITICAL A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request. | Jul 7, 2022 | 9.8 | 61 | NO | NO |
CVE-2021-31324CRITICAL The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution. | May 18, 2021 | 9.8 | 59 | NO | YES |
CVE-2019-13360CRITICAL In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username. | Jul 16, 2019 | 9.8 | 55 | NO | YES |
CVE-2018-18322CRITICAL CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, o | Oct 15, 2018 | 9.8 | 49 | NO | YES |
CVE-2020-10230CRITICAL CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter. | Mar 16, 2020 | 9.8 | 48 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (85 CVEs).
CISA KEV
2 CVEs
2.4% of CVEs· 96th percentile
Metasploit
1 CVE
1.2% of CVEs· 96th percentile
Nuclei
6 CVEs
7.1% of CVEs· 97th percentile
ExploitDB
14 CVEs
16.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (85 CVEs).
Media Mentions
Signals from CVEs in this product scope (85 CVEs).
Top CNAs Publishing CVEs For Webpanel
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9.8.923 | 37 | 9.1 | 6.8% | 0 | 0 |
| 0.9.8.891 | 1 | 9.8 | 8.1% | 0 | 0 |
| 0.9.8.855 | 1 | 4.6 | 0.5% | 0 | 0 |
| 0.9.8.851 | 10 | 5.0 | 1.8% | 0 | 0 |
| 0.9.8.848 | 1 | 5.3 | 4.0% | 0 | 0 |
| 0.9.8.846 | 1 | 6.1 | 2.2% | 0 | 0 |
| 0.9.8.840 | 1 | 4.3 | 2.0% | 0 | 0 |
| 0.9.8.837 | 2 | 7.1 | 3.6% | 0 | 0 |
| 0.9.8.836 | 4 | 7.8 | 19.9% | 0 | 4 |
| 0.9.8.807 | 1 | 4.8 | 5.9% | 0 | 1 |
| 0.9.8.793 | 1 | 4.8 | 5.9% | 0 | 1 |
| 0.9.8.753 | 1 | 4.8 | 5.9% | 0 | 1 |
| 0.9.8.480 | 3 | 7.8 | 29.7% | 0 | 3 |
| 0.9.8.1152 | 4 | 8.8 | 1.5% | 0 | 0 |
| 0.9.8.1126 | 2 | 7.3 | 10.2% | 0 | 0 |