31
Information / Re: Possible CWP Security Issue – Malicious JavaScript Injection
« Last post by overseer on August 29, 2026, 10:51:17 PM »Look for a file named test123zz in your web roots:
ls -al /home/*/public_html/test123zz
ls -al /home/*/public_html/test123zz
32
Backup / Backup Manager Beta is not remembering password in destination
« Last post by clight77 on August 29, 2026, 03:00:58 PM »Backup Manager Beta is not remembering password in destination and will not do an automatic BU, but re typing in the password will allow you to do a manual BU.
Just info
Just info

33
PHP / Re: PHP-FPM Won't install zlib says missing dependency zlib-dir
« Last post by Starburst on August 28, 2026, 10:15:14 PM »Well this bug still exists in CWP 1.10 with PHP 8.4 and 8.5
Even using PHP Switcher.
Installed zlib with dnf and manually.
PHP 8.3.x works OK.
Even using PHP Switcher.
Installed zlib with dnf and manually.
PHP 8.3.x works OK.
34
Mod_Security / Re: allowed http versions mod security
« Last post by Starburst on August 28, 2026, 09:40:09 PM »To update Apache to the latest with HTTP/2 you can see:
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/update-apache-http-2-to-2-4-68-in-cwp-on-almalinux-8-9/
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/update-apache-http-2-to-2-4-68-in-cwp-on-almalinux-8-9/
36
Mod_Security / Re: allowed http versions mod security
« Last post by cyberspace on August 28, 2026, 09:36:30 PM »Make sure mod_http2 is updated and disable the mod_security rule 960034 as suggests @overseer.
Check this thread to find how to update mod_http2:
https://forum.centos-webpanel.com/apache/http2-bomb-remote-dos-exploit-hits-nginx-apache-iis-envoy-and-cloudflare/
Check this thread to find how to update mod_http2:
https://forum.centos-webpanel.com/apache/http2-bomb-remote-dos-exploit-hits-nginx-apache-iis-envoy-and-cloudflare/
37
Mod_Security / Re: allowed http versions mod security
« Last post by Starburst on August 28, 2026, 06:20:39 PM »Curious also why you are running OWASP CRS v2.2.9
v4.29.0 was release about 2 weeks ago.
v4.29.0 was release about 2 weeks ago.
38
Mod_Security / Re: allowed http versions mod security
« Last post by overseer on August 28, 2026, 04:46:54 PM »You could add 960034 to your global disabled rules...
39
Information / Re: Possible CWP Security Issue – Malicious JavaScript Injection
« Last post by overseer on August 28, 2026, 04:45:12 PM »Thanks, Netino. Your write-up was very clear, insightful and much appreciated!
40
Backup / Re: Error/bug when starting a backup
« Last post by André Bastos on August 28, 2026, 11:49:22 AM »HI, please update to the latest version that was released today
Solved. Thanks
Recent Posts