CVE-2022-44877CISA KEVEPSS p100.0%

CVE-2022-44877CWP Control Web Panel OS Command Injection Vulnerability

CWP / Control Web Panel

Description

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100.00% probability of exploitation · percentile 100.0% · 2026-06-28T12:03:37Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2023-01-17

(incoming)1

TypeTargetConfidenceTier
KEVEntryCWP Control Web Panel OS Command Injection Vulnerabilitykev-cve-2022-448770%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CyberPanel Incorrect Default Permissions Vulnerability
CVE
Cacti Command Injection Vulnerability
CVE
CVE-2025-56413
CVE
CVE-2026-24452
CVE
Webmin Command Injection Vulnerability
CVE
CVE-2026-24689
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.