📦 Webpanel

by Control Webpanel

🔍 What is Webpanel?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-48703

CRITICAL CVSS 9.0 Sep 19, 2025

CVE-2025-48703 allows unauthenticated attackers to execute arbitrary commands on CWP (Control Web Panel) servers by injecting shell metacharacters into the t_total parameter. This affects all CWP inst...

CVE-2023-42121

CRITICAL CVSS 9.8 May 3, 2024

CVE-2023-42121 is a critical authentication bypass vulnerability in Control Web Panel that allows remote attackers to execute arbitrary code without authentication. This affects all systems running vu...

CVE-2022-25046

CRITICAL CVSS 9.8 Jul 7, 2022

CVE-2022-25046 is a critical path traversal vulnerability in CentOS Web Panel (CWP) that allows unauthenticated attackers to execute arbitrary code on affected servers. Attackers can exploit this by s...

CVE-2021-31316

CRITICAL CVSS 9.8 May 18, 2021

This SQL injection vulnerability in CentOS Web Panel's unprivileged user portal allows attackers to execute arbitrary SQL commands via the 'idsession' parameter. Successful exploitation can lead to re...

CVE-2021-31324

CRITICAL CVSS 9.8 May 18, 2021

CVE-2021-31324 is a command injection vulnerability in CentOS Web Panel's unprivileged user portal that allows attackers to execute arbitrary commands with root privileges. This affects all CentOS Web...

CVE-2023-42123

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Control Web Panel installations. Attackers can exploit improper input validation in the m...

CVE-2023-42120

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Control Web Panel installations. The flaw exists in the dns_zone_editor module where user...

CVE-2022-25048

HIGH CVSS 8.8 Jul 7, 2022

CVE-2022-25048 is a command injection vulnerability in CentOS Web Panel (CWP) that allows authenticated users to execute arbitrary commands with root privileges. This affects CWP installations where n...