This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
1
E-Mail / Re: New Roundcube 1.6 version failed
« on: June 24, 2026, 03:35:27 PM »
I'm going to fuck with cwp, I'm at the end of my patience, I tried to upgrade to roundcube, error!!!, I used Starburst's script, then I get an internal server error in roundcube, it doesn't see my emails, if I use Sandeep's script it goes, until the next update, 1.5.16 - where does it give me a php error, it asks for php 7.3
)))))), seriously??? and do you see the solution to put it on a user with a subdomain? but what are these gibberish
))), is this normal? I tried to put fresh cwp on almalinux9 yesterday, the latest version according to the documentation on the forum, do you want to upgrade to Ana-Maria-Database - cwp is broken, nginx 1.14??, it's a joke!!!
)))))), seriously??? and do you see the solution to put it on a user with a subdomain? but what are these gibberish
))), is this normal? I tried to put fresh cwp on almalinux9 yesterday, the latest version according to the documentation on the forum, do you want to upgrade to Ana-Maria-Database - cwp is broken, nginx 1.14??, it's a joke!!!2
CentOS-WebPanel Bugs / Re: I think there is a very serious security vulnerability in CWP right now.
« on: June 16, 2026, 10:34:54 AM »
CWP should handle the basics. The default installation is several versions behind the current ones.
While we can do manual updates, if CWP later updates its default version, it can break things because we are no longer running a default CWP installation.
If we all agree that the default installation is several versions behind and that manually upgrading core components can create compatibility issues later, then the obvious question is:
What is the solution?
Continuing to rely on manual upgrades after every fresh installation is not really a solution, especially for those of us managing multiple VPSs and production environments.
Is there a plan to update the installation script and the default software stack?
Is there a roadmap for bringing the default installation in line with current stable versions of MariaDB, Apache, Nginx, phpMyAdmin, Roundcube and PHP?
Because from an administrator's perspective, a fresh installation should already provide a modern and secure baseline instead of requiring immediate post-installation upgrades and forum-based workarounds.
3
CentOS-WebPanel Bugs / Re: I think there is a very serious security vulnerability in CWP right now.
« on: June 15, 2026, 06:44:43 PM »
Starburst — I know you are active here on the forum, I’ve been following your replies, and I appreciate the work you are doing.
However, before any workaround solutions are suggested, I want to clarify something important.
A few months ago, I opened a support ticket on the CWP platform regarding this issue. @josemnunez was aware of it and had reviewed my report, but after I continued to insist on the same concern, the ticket was closed without any real resolution.
If this is a financial or resource issue, then that is fine — increase the license price, even double it if necessary. I personally would agree to that.
But what should not continue is the current approach based on patchwork fixes and temporary solutions for core issues in CWP.
At this point, I would like to restate the main issue clearly:
I would like to clarify and consolidate my previous points regarding the CWP installation process and the default stack on AlmaLinux 8/9.
This is not about choosing between Nginx, Apache, or any specific web server. The issue is the default state and quality of a fresh CWP installation.
At the moment, a clean installation of CWP on AlmaLinux 8/9 results in an outdated and inconsistent software stack, including older versions of core components such as:
MariaDB
Apache
Nginx (if selected)
PHP (non-modern default setup)
phpMyAdmin
Roundcube
Postfix
system packages related to web and security that are not aligned with current security standards
This means that immediately after installation, we are forced to manually update multiple critical components just to reach a modern, secure, and stable state. As you already know, this update process is not always straightforward and can sometimes introduce issues based on forum-provided solutions, which is not ideal for production environments.
What I am suggesting is a modern secure baseline for new installations:
On AlmaLinux 8/9, CWP should install by default a modern and secure stack:
PHP 8.3+ as system default
latest stable MariaDB
latest stable Apache
latest stable Roundcube
phpMyAdmin updated according to current security standards
If Nginx is selected during installation, it should also be installed in its latest stable version, not an outdated one.
In addition, there is another important issue:
On AlmaLinux 9, CWP installation requires additional packages to be installed manually before running the installation script. However, this is not clearly documented in the official installation guide. These requirements and workarounds were originally published on the forum during the Beta stage. Since AlmaLinux 9 is now officially supported, these prerequisites should either be integrated into the installation script or documented officially.
A fresh installation should not require users to search forums for known prerequisites or fixes.
At some point, the installation process and default stack need to be properly modernized instead of constantly relying on temporary solutions.
However, before any workaround solutions are suggested, I want to clarify something important.
A few months ago, I opened a support ticket on the CWP platform regarding this issue. @josemnunez was aware of it and had reviewed my report, but after I continued to insist on the same concern, the ticket was closed without any real resolution.
If this is a financial or resource issue, then that is fine — increase the license price, even double it if necessary. I personally would agree to that.
But what should not continue is the current approach based on patchwork fixes and temporary solutions for core issues in CWP.
At this point, I would like to restate the main issue clearly:
I would like to clarify and consolidate my previous points regarding the CWP installation process and the default stack on AlmaLinux 8/9.
This is not about choosing between Nginx, Apache, or any specific web server. The issue is the default state and quality of a fresh CWP installation.
At the moment, a clean installation of CWP on AlmaLinux 8/9 results in an outdated and inconsistent software stack, including older versions of core components such as:
MariaDB
Apache
Nginx (if selected)
PHP (non-modern default setup)
phpMyAdmin
Roundcube
Postfix
system packages related to web and security that are not aligned with current security standards
This means that immediately after installation, we are forced to manually update multiple critical components just to reach a modern, secure, and stable state. As you already know, this update process is not always straightforward and can sometimes introduce issues based on forum-provided solutions, which is not ideal for production environments.
What I am suggesting is a modern secure baseline for new installations:
On AlmaLinux 8/9, CWP should install by default a modern and secure stack:
PHP 8.3+ as system default
latest stable MariaDB
latest stable Apache
latest stable Roundcube
phpMyAdmin updated according to current security standards
If Nginx is selected during installation, it should also be installed in its latest stable version, not an outdated one.
In addition, there is another important issue:
On AlmaLinux 9, CWP installation requires additional packages to be installed manually before running the installation script. However, this is not clearly documented in the official installation guide. These requirements and workarounds were originally published on the forum during the Beta stage. Since AlmaLinux 9 is now officially supported, these prerequisites should either be integrated into the installation script or documented officially.
A fresh installation should not require users to search forums for known prerequisites or fixes.
At some point, the installation process and default stack need to be properly modernized instead of constantly relying on temporary solutions.
4
CentOS-WebPanel Bugs / Re: I think there is a very serious security vulnerability in CWP right now.
« on: June 15, 2026, 04:16:58 PM »This issue has been resolved on all CWP servers since last week, thank you for reporting it as well.
I would like to raise again an important concern regarding the CWP installation script.
Currently, the default installation does not provide a modern and secure stack out of the box. After installing AlmaLinux 8 or 9, it is necessary to manually update multiple core components (NGINX, MariaDB, PHP, Apache, etc.) in order to reach current stable and secure versions without known CVEs.
This process is time-consuming and becomes especially difficult when managing multiple servers (20–25 CWP Pro VPS instances), where consistency and automation are essential.
My suggestion is not to remove legacy support, but to improve the installer by offering a modern default stack option, including:
PHP 8.3+ as default
Latest stable versions of NGINX and MariaDB
Roundcube and Apache updated accordingly
While still allowing legacy PHP versions (such as 7.4) to be installed and selected per domain through “Manage WebServers Configuration”
This would significantly improve security, deployment speed, and server standardization, especially for multi-server environments.
I have raised this concern previously on the forum, but I have not received an official response from the CWP team.
I would appreciate an official clarification on whether this improvement is planned or considered.
5
Apache / Re: HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare
« on: June 05, 2026, 07:14:55 AM »
Unfortunately, as many users can see, only Starburst and Overseer seem to be actively helping on the forum, and they do their best to support the community. I appreciate their efforts.
However, I am disappointed by the lack of communication from the CWP team. I currently maintain 20 active CWP PRO servers. Three of them are running AlmaLinux 8, while the rest are still on CentOS 7 because I do not yet consider the AlmaLinux 9 version ready for production use.
I would genuinely like to be proven wrong, but with solid technical arguments.
Starburst and Overseer, please do not take this personally. I have always tried to contribute constructively on this forum.
My concern is simple: the AlmaLinux 9 branch of CWP remained in BETA for more than a year. Now that it has been officially released and promoted as a supported platform, why does a fresh installation still deploy outdated packages and service versions? After such a long beta period, many of us expected a more modern, secure, and production-ready software stack by default.
I have deployed CWP solutions for multiple clients in addition to my own VPS infrastructure. The reality is that we cannot continue operating indefinitely with outdated components while new CVEs are published every few days and remain unresolved.
On AlmaLinux 8, I was forced to manually update Nginx, Apache, MariaDB, and Roundcube. This process generated several operational issues, which I eventually resolved using a combination of Starburst’s forum posts and solutions from the AlphaGNU forum. While acceptable on a single server, this approach does not scale when managing dozens of production VPS instances and client environments.
In CWP, I have repeatedly faced inconsistencies in managing core stack components such as Nginx, Apache, MariaDB, PHP (including multiple versions and updates), Roundcube, and Varnish. Support for newer versions appears inconsistent across panel releases, and in practice installation or upgrade processes frequently lead to dependency conflicts, broken configurations, or service instability.
This creates a serious challenge in maintaining stable production environments across multiple servers.
What many of us are asking for is not another temporary patch, but a clear direction and active communication from the CWP development team. At the moment, the official administrators and support channels appear largely silent, and this creates uncertainty for users who rely on CWP in production environments.
I believe many long-term CWP PRO customers would appreciate greater transparency on these points.
This message does not come from someone testing CWP in a lab environment. It comes from a paying customer who manages 20 active CWP PRO servers and has deployed CWP solutions for multiple clients over the years. The intention is not criticism for its own sake, but a request for clarity, consistency, and more reliable long-term platform maintenance.
However, I am disappointed by the lack of communication from the CWP team. I currently maintain 20 active CWP PRO servers. Three of them are running AlmaLinux 8, while the rest are still on CentOS 7 because I do not yet consider the AlmaLinux 9 version ready for production use.
I would genuinely like to be proven wrong, but with solid technical arguments.
Starburst and Overseer, please do not take this personally. I have always tried to contribute constructively on this forum.
My concern is simple: the AlmaLinux 9 branch of CWP remained in BETA for more than a year. Now that it has been officially released and promoted as a supported platform, why does a fresh installation still deploy outdated packages and service versions? After such a long beta period, many of us expected a more modern, secure, and production-ready software stack by default.
I have deployed CWP solutions for multiple clients in addition to my own VPS infrastructure. The reality is that we cannot continue operating indefinitely with outdated components while new CVEs are published every few days and remain unresolved.
On AlmaLinux 8, I was forced to manually update Nginx, Apache, MariaDB, and Roundcube. This process generated several operational issues, which I eventually resolved using a combination of Starburst’s forum posts and solutions from the AlphaGNU forum. While acceptable on a single server, this approach does not scale when managing dozens of production VPS instances and client environments.
In CWP, I have repeatedly faced inconsistencies in managing core stack components such as Nginx, Apache, MariaDB, PHP (including multiple versions and updates), Roundcube, and Varnish. Support for newer versions appears inconsistent across panel releases, and in practice installation or upgrade processes frequently lead to dependency conflicts, broken configurations, or service instability.
This creates a serious challenge in maintaining stable production environments across multiple servers.
What many of us are asking for is not another temporary patch, but a clear direction and active communication from the CWP development team. At the moment, the official administrators and support channels appear largely silent, and this creates uncertainty for users who rely on CWP in production environments.
I believe many long-term CWP PRO customers would appreciate greater transparency on these points.
This message does not come from someone testing CWP in a lab environment. It comes from a paying customer who manages 20 active CWP PRO servers and has deployed CWP solutions for multiple clients over the years. The intention is not criticism for its own sake, but a request for clarity, consistency, and more reliable long-term platform maintenance.
6
Apache / Re: HTTP/2 Bomb — Remote DoS Exploit Hits nginx, Apache, IIS, Envoy, and Cloudflare
« on: June 04, 2026, 11:43:49 AM »
Hello admins, only if someone screams and threatens, one step forward and of course 2 back, it seems that cwp advances like this, 1 forward 2 back. Even now the cwp installation script has not been corrected, still with the outdated packages and services to install. So that after installation you have to update Apache, Roundcube, Nginx, MariaDB, PhP ... so on ... Who is the admin of this forum and if he is from the CWP team, can he tell here what is the status of the new version (which comes with a never-before-seen interface) and the changelog of the latest versions?
"If you are running Apache <2.4.67 or Nginx <1.29.7, Please update ASAP."
Starburst - and what are the correct steps to update Apache - without breaking anything in cwp?
Same for NGINX, same for Roundcube! MariaDB?
I've been watching the HestiaCP forum these days, incredible, a problem appeared, you automatically have a solution .... here even when I open a ticket, for paid servers with a license, you get a response like "I'm sick of you".
Too bad, if the team was more serious, cwp would be an incredible control panel!
"If you are running Apache <2.4.67 or Nginx <1.29.7, Please update ASAP."
Starburst - and what are the correct steps to update Apache - without breaking anything in cwp?
Same for NGINX, same for Roundcube! MariaDB?
I've been watching the HestiaCP forum these days, incredible, a problem appeared, you automatically have a solution .... here even when I open a ticket, for paid servers with a license, you get a response like "I'm sick of you".
Too bad, if the team was more serious, cwp would be an incredible control panel!
7
Updates / Re: CWP7: 0.9.8.1228
« on: May 27, 2026, 03:02:12 PM »
since the changelog on the official website does not publish any information about the new updates, the version from 0.9.8.1226 to 0.9.8.1228 does not represent anything - except that it auto-incremented +1
)))))))) am I wrong at this point?
)))))))) am I wrong at this point?
8
CentOS-WebPanel Bugs / Re: CentOS 9 stream CWP installation problem
« on: May 09, 2026, 12:23:26 PM »From a clean AL9 install:
If there are a few packages already installed, don't worry.Code: [Select]dnf install dnf-plugins-coreCode: [Select]dnf install elrepo-release epel-release -y
..............................
Hello everyone,
Can anyone help me with this issue? I’ve tried 5–6 times on fresh VPS installations with AlmaLinux 9 Minimal. After installing CWP Panel, I try to upgrade MariaDB, but it always fails. I followed the procedures and steps shared by Sandeep B. and Starburst, but no luck so far.
If I use AlmaLinux 8 instead, the MariaDB upgrade works correctly, unlike on AlmaLinux 9. I’m not saying everything is perfect on AlmaLinux 8, but at least the MariaDB upgrade process completes successfully there.
Also, regarding the CWP installation on AlmaLinux 9: nowhere on the official website does it clearly mention that all the additional packages and configurations shared here on the forum need to be installed manually.
Wouldn’t it make more sense to update the sh cwp-el9-latest installation script so it installs newer and fully compatible versions of Apache, Nginx, MariaDB, Postfix, Dovecot, Roundcube, and the other required services by default?
Honestly, every time we open a more serious ticket with the CWP team, it gets closed quickly and we are redirected to the forum or support email, and then asked to leave a review for the response or “solution” we received. 🙂
What do you guys think?
9
Updates / Re: Upladte 0.9.8.1225
« on: May 09, 2026, 12:07:05 PM »Thanks.
But how to activate Git Options and Cloudflare I get errors trying to using cloudflare and trying to active git on all accounts
From Admin - >Script Installer->Git Manager, but I haven't tested if it works, at least CloudFlare appears in User Acc, but if you access it it gives an error
10
Information / Re: Modernizing CWP: Drop EOL, Support AL9, AL10 & Rocky
« on: April 02, 2026, 12:47:59 PM »
We have the cwp panel 9 version - which on the official website is no longer BETA, it appears as the official recommended version.
If we install from 0 almalinux 9 - and then cwp panel the latest version, according to the procedure on the site, still a lot of bugs, for example:
Setup default Web Servers nginx+varnish+apache, but you will see that varnish does not work, if you install it manually at Varnish Conf this notification appears: Varnish NOT installed or conf file /etc/varnish/varnish.params does not exist
On CentOS 8 you can edit file: /usr/lib/systemd/system/varnish.service,
then at the clamd email services - it runs permanently, if I send myself an email from g-mail it enters the inbox at cwp test@mycompany.com after 10 minutes, (all zones configured correctly, dns, all impeccable, all perfect on mxtoolbox),
the spamassasin service has an error: razor2: razor2 check failed: No such file or directory razor2: Can't read: /var/lib/razor/ at /usr/share/perl5/vendor_perl/Mail/SpamAssassin/Plugin/Razor2.pm line 331. ,
another situation, CSF LFD firewall, if you do not disable SELINUX MANUALLY, it does not work....
and we do not know in the end if the vulnerabilities have been resolved.
I saw that version 0.9.8.1224 appeared - but again we do not know any changelog.
Attention I am talking here about cwp PRO, and many servers, with which we are in standbay to see where we are heading, migrate to another solution or come with clear news about what is happening
Quick guide EL9/ Almalinux 9
hostnamectl set-hostname srv.example.com
dnf install epel-release -y
dnf -y install wget
dnf -y update
reboot
cd /usr/local/src
wget http://centos-webpanel.com/cwp-el9-latest
sh cwp-el9-latest
if there is an advanced setup, which will work all the services as they should, why don't you post it? (I see that you have: Order Installation from Experts for $5.49) - for what?
If we install from 0 almalinux 9 - and then cwp panel the latest version, according to the procedure on the site, still a lot of bugs, for example:
Setup default Web Servers nginx+varnish+apache, but you will see that varnish does not work, if you install it manually at Varnish Conf this notification appears: Varnish NOT installed or conf file /etc/varnish/varnish.params does not exist
On CentOS 8 you can edit file: /usr/lib/systemd/system/varnish.service,
then at the clamd email services - it runs permanently, if I send myself an email from g-mail it enters the inbox at cwp test@mycompany.com after 10 minutes, (all zones configured correctly, dns, all impeccable, all perfect on mxtoolbox),
the spamassasin service has an error: razor2: razor2 check failed: No such file or directory razor2: Can't read: /var/lib/razor/ at /usr/share/perl5/vendor_perl/Mail/SpamAssassin/Plugin/Razor2.pm line 331. ,
another situation, CSF LFD firewall, if you do not disable SELINUX MANUALLY, it does not work....
and we do not know in the end if the vulnerabilities have been resolved.
I saw that version 0.9.8.1224 appeared - but again we do not know any changelog.
Attention I am talking here about cwp PRO, and many servers, with which we are in standbay to see where we are heading, migrate to another solution or come with clear news about what is happening
Quick guide EL9/ Almalinux 9
hostnamectl set-hostname srv.example.com
dnf install epel-release -y
dnf -y install wget
dnf -y update
reboot
cd /usr/local/src
wget http://centos-webpanel.com/cwp-el9-latest
sh cwp-el9-latest
if there is an advanced setup, which will work all the services as they should, why don't you post it? (I see that you have: Order Installation from Experts for $5.49) - for what?
11
Information / Re: Modernizing CWP: Drop EOL, Support AL9, AL10 & Rocky
« on: March 20, 2026, 06:03:22 PM »
Hello everyone,
I agree with your proposal, but, have you ever checked your servers? For example shodan.io, then enter the public IP of the server or the IP to which the cwp server is connected and you will be amazed how many vulnerabilities you will find in the CWP Control Panel, regardless of whether you have servers with centos7 or almalinux, these CVEs must be resolved, when installing bring the latest versions of apache, nginx, mariadb, postfix, dovecot, roundcube (here is the big problem already, a lot of email accounts injected into sieve - with forward on all incoming emails)..etc, not to mention all the publications on CISA - the US Security Agency.
I have 20 cwp panel pro servers, and I don't know what to do, where to choose.
I know there are many control panels but I don't want to give up on cwp panel.
They say that a new version is coming, a new interface, what do we do then? Do we migrate the servers again? Are the security issues being resolved? What firewall will be in the new versions? CSF - LFD is dead.....
They don't say anything that will be resolved in the 2024 updates (and then the issue was ambiguous), they just change the version.
Check your servers on shodan.io or another site that can check vulnerabilities! Let's see then how things are with cwp!
Good luck
I agree with your proposal, but, have you ever checked your servers? For example shodan.io, then enter the public IP of the server or the IP to which the cwp server is connected and you will be amazed how many vulnerabilities you will find in the CWP Control Panel, regardless of whether you have servers with centos7 or almalinux, these CVEs must be resolved, when installing bring the latest versions of apache, nginx, mariadb, postfix, dovecot, roundcube (here is the big problem already, a lot of email accounts injected into sieve - with forward on all incoming emails)..etc, not to mention all the publications on CISA - the US Security Agency.
I have 20 cwp panel pro servers, and I don't know what to do, where to choose.
I know there are many control panels but I don't want to give up on cwp panel.
They say that a new version is coming, a new interface, what do we do then? Do we migrate the servers again? Are the security issues being resolved? What firewall will be in the new versions? CSF - LFD is dead.....
They don't say anything that will be resolved in the 2024 updates (and then the issue was ambiguous), they just change the version.
Check your servers on shodan.io or another site that can check vulnerabilities! Let's see then how things are with cwp!
Good luck
12
CentOS 7 Problems / Re: Disk Quota
« on: June 16, 2022, 08:53:39 AM »
unfortunately this problem is not solved even now, I also opened tickets but I see that priority has for example: Streaming Manager: Shoutcast + Icecast + AutoDJ, that this was needed for the development of cwp panel and not the needs and problems reported in tickets and on the forum
copy paste documentation from 3 different places,
I say decide how right it is?
rGRUB_CMDLINE_LINUX = "crashkernel = auto rd.lvm.lv = cl / root rd.lvm.lv = cl / swap rhgb quiet rootflags = uquota, pquota" and "/ dev / mapper / centos_root-home / home xfs defaults, usrquota, grpquota 0 0 ", if the admin says that the centos 7 server is not configured correctly, why not put the correct documentation here, from the server configuration (how to make partitions ...), grub configuration, fstab ... so on
copy paste documentation from 3 different places,
I say decide how right it is?
rGRUB_CMDLINE_LINUX = "crashkernel = auto rd.lvm.lv = cl / root rd.lvm.lv = cl / swap rhgb quiet rootflags = uquota, pquota" and "/ dev / mapper / centos_root-home / home xfs defaults, usrquota, grpquota 0 0 ", if the admin says that the centos 7 server is not configured correctly, why not put the correct documentation here, from the server configuration (how to make partitions ...), grub configuration, fstab ... so on
13
Updates / Re: Problems with update 0.9.8.1136
« on: May 21, 2022, 07:13:51 AM »hey admin! Does it take longer to fix the problems? I have 18 servers + 3 more in another location and I look at them like an ox at a new gate. What are we doing ? do we switch to cPanel, Plesk, DirectAdmin, InterWORX?
The updates have been crashing lately, please let us know in advance if the CWP project will end, just like VESTACP
what issue do you have with the server, have you checked before real top usage before from the shell ?
That top 5 processes in cwp dashboard is related to some ajax slower response and not the real issue.
you mean we're all talking nonsense here and cwp pro panel is fine, it works perfectly, we agreed in private to make posts, i pay cwp pro licenses for all servers, i have low expectations from cwp this problem needs to be fixed, say here in front of everyone, to know what we have to do, I have been working with cwp pro for 6, 7 years, it would be a shame to give it up.
14
Updates / Re: Problems with update 0.9.8.1136
« on: May 20, 2022, 06:34:41 PM »
hey admin! Does it take longer to fix the problems? I have 18 servers + 3 more in another location and I look at them like an ox at a new gate. What are we doing ? do we switch to cPanel, Plesk, DirectAdmin, InterWORX?
The updates have been crashing lately, please let us know in advance if the CWP project will end, just like VESTACP
The updates have been crashing lately, please let us know in advance if the CWP project will end, just like VESTACP
15
Updates / Re: Problems with update 0.9.8.1138
« on: May 19, 2022, 05:57:18 AM »
18 servers with cwp pro, all are over 63% CPU, please solve the problem as soon as possible and next time do not update without testing them.
