Control Webpanel: community verdicts
2 notable / known-exploited Control Webpanel CVEs the community has triaged.
ⓘ Not an exhaustive list: we focus on the findings that matter (exploited / notable). For every Control Webpanel CVE, see NVD ↗.
- CVE-2022-44877CRIT 9.8KEVEPSS 100%
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
- CVE-2025-48703CRIT 9KEVEPSS 100%
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.