VYPR

Cwp

by Control By Web

CVEs (2)

  • CVE-2018-18772HigNov 20, 2018
    risk 0.60cvss 8.8epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.

  • CVE-2025-67888HigMay 8, 2026
    risk 0.51cvss 7.3epss 0.04

    An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated…