Webpanel

Vendor:

First CVE: Jan 22, 2018 · Active for 8 years

85
Total CVEs
More Total CVEs than 99% of tracked products
10.6
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
2.4%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Webpanel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2018
8 years ago
Most Recent CVE
Sep 19, 2025
308 days ago

CVE Severity & Scoring

Webpanel85 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local2 (2.4%)
Network83 (97.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low82 (96.5%)
High3 (3.5%)
Unknown0 (0.0%)
User Interaction
None72 (84.7%)
Unknown0 (0.0%)
Required13 (15.3%)
Privileges Required
Low21 (24.7%)
High2 (2.4%)
None62 (72.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (85 CVEs).

85 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the logi
Jan 5, 20239.899YESYES
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager ch
Sep 19, 20259.098YESYES
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as d
Dec 26, 20229.880NOYES
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.
Oct 15, 20187.579NOYES
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /
Dec 26, 20229.862NONO
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
Jul 7, 20229.861NONO
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
May 18, 20219.859NOYES
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging knowledge of a valid username.
Jul 16, 20199.855NOYES
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, o
Oct 15, 20189.849NOYES
CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.
Mar 16, 20209.848NOYES

Exploit Exposure

Signals from CVEs in this product scope (85 CVEs).

CISA KEV
2 CVEs
2.4% of CVEs· 96th percentile
Metasploit
1 CVE
1.2% of CVEs· 96th percentile
Nuclei
6 CVEs
7.1% of CVEs· 97th percentile
ExploitDB
14 CVEs
16.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (85 CVEs).

Media Mentions

Signals from CVEs in this product scope (85 CVEs).

Top CNAs Publishing CVEs For Webpanel

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.9.8.923379.16.8%00
0.9.8.89119.88.1%00
0.9.8.85514.60.5%00
0.9.8.851105.01.8%00
0.9.8.84815.34.0%00
0.9.8.84616.12.2%00
0.9.8.84014.32.0%00
0.9.8.83727.13.6%00
0.9.8.83647.819.9%04
0.9.8.80714.85.9%01
0.9.8.79314.85.9%01
0.9.8.75314.85.9%01
0.9.8.48037.829.7%03
0.9.8.115248.81.5%00
0.9.8.112627.310.2%00