← Back

Centos Webpanel

centos-webpanel

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Centos Webpanel
1Centos Web Panel
Jun 17, 2026
Jul 28, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When parsing the service_stop parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9726.Show less
1Centos Webpanel
1Centos Web Panel
Jun 17, 2026
Aug 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover phpMyAdmin passwords (of any user in /etc/passwd) via an attacker account.
1Centos Webpanel
1Centos Web Panel
Jun 17, 2026
Aug 21, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete databases (such as oauthv2) from the server via an attacker account.
1Centos Webpanel
1Centos Web Panel
Jun 17, 2026
Jul 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attackers to execute a shell command, i.e., obtain a reverse shell with user privilege.
1Centos Webpanel
1Centos Web Panel
Jun 17, 2026
Apr 18, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. By chan...Show more
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to Stored/Persistent XSS for Admin Email fields on the "CWP Settings > "Edit Settings" screen. By changing the email ID to any XSS Payload and clicking on Save Changes, the XSS Payload will execute.Show less
1Centos Webpanel
1Centos Web Panel
Jun 17, 2026
Apr 3, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fields via a "DNS Functions" "Edit Nameservers IPs" action.