41
Information / Re: Possible CWP Security Issue – Malicious JavaScript Injection
« Last post by overseer on August 30, 2026, 11:55:29 AM »42
Backup / Re: Backup Manager Beta is not remembering password in destination
« Last post by xenios on August 30, 2026, 10:42:17 AM »Same here
43
Information / Re: Possible CWP Security Issue – Malicious JavaScript Injection
« Last post by overseer on August 29, 2026, 10:51:17 PM »Look for a file named test123zz in your web roots:
ls -al /home/*/public_html/test123zz
ls -al /home/*/public_html/test123zz
44
Backup / Backup Manager Beta is not remembering password in destination
« Last post by clight77 on August 29, 2026, 03:00:58 PM »Backup Manager Beta is not remembering password in destination and will not do an automatic BU, but re typing in the password will allow you to do a manual BU.
Just info
Just info

45
PHP / Re: PHP-FPM Won't install zlib says missing dependency zlib-dir
« Last post by Starburst on August 28, 2026, 10:15:14 PM »Well this bug still exists in CWP 1.10 with PHP 8.4 and 8.5
Even using PHP Switcher.
Installed zlib with dnf and manually.
PHP 8.3.x works OK.
Even using PHP Switcher.
Installed zlib with dnf and manually.
PHP 8.3.x works OK.
46
Mod_Security / Re: allowed http versions mod security
« Last post by Starburst on August 28, 2026, 09:40:09 PM »To update Apache to the latest with HTTP/2 you can see:
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/update-apache-http-2-to-2-4-68-in-cwp-on-almalinux-8-9/
https://starburst.help/control-web-panel-cwp/control-web-panel-cwp-admin-tutorials/update-apache-http-2-to-2-4-68-in-cwp-on-almalinux-8-9/
48
Mod_Security / Re: allowed http versions mod security
« Last post by cyberspace on August 28, 2026, 09:36:30 PM »Make sure mod_http2 is updated and disable the mod_security rule 960034 as suggests @overseer.
Check this thread to find how to update mod_http2:
https://forum.centos-webpanel.com/apache/http2-bomb-remote-dos-exploit-hits-nginx-apache-iis-envoy-and-cloudflare/
Check this thread to find how to update mod_http2:
https://forum.centos-webpanel.com/apache/http2-bomb-remote-dos-exploit-hits-nginx-apache-iis-envoy-and-cloudflare/
49
Mod_Security / Re: allowed http versions mod security
« Last post by Starburst on August 28, 2026, 06:20:39 PM »Curious also why you are running OWASP CRS v2.2.9
v4.29.0 was release about 2 weeks ago.
v4.29.0 was release about 2 weeks ago.
50
Mod_Security / Re: allowed http versions mod security
« Last post by overseer on August 28, 2026, 04:46:54 PM »You could add 960034 to your global disabled rules...
Recent Posts