v2.3.4 Stable
Dated: 25th April 2023
Note: We’ve also released our API Docs: CyberPanel Cloud API
I am happy to announce that CyberPanel v2.3.4 has been released. This update brings tons of features including support for Ubuntu 22 and bug fixes to CyberPanel.
Features
- SSL v2 - Wild Card SSLs and Cloudflare Integration
- Backups v2 - Fast, Secure and Incremental Backups
Bugs
- bug fix: email debugger · usmannasir/cyberpanel@6cb68a6 · GitHub
- Add path option to createChild function
- bug fix: #1019, this should refresh mail ssl incase its expired/renewd
- possible fix of https://community.cyberpanel.net/t/snappymail-does-no…
- remove the need for adding folders manually
- update logic for refresh lic
- possible bug fix on ubuntu 22 upgrade
- ChangeLinuxUserPassword
- bug fix with external app
- bug fix: change package by owner
- add php8.1 to lsws config
- SSL Bug fix
- bug fix: for the view when docker is not installed
- bug fix: ftp issue on ubuntu22
v2.3.3 Stable
Dated: 23rd Jan 2023
Note: We’ve also released our API Docs: CyberPanel Cloud API
I am happy to announce that CyberPanel v2.3.3 has been released. This update brings tons of features including support for Ubuntu 22 and bug fixes to CyberPanel.
Features
Bugs
- bug fix: incremental backups for s3
- add some changes in mailscanner
- some bug fixes in wp remote backups;
- bug fix: wp scheduled backups
- add missing tables;
- scanwpsite
- upgrade snappy version
- replace lscpd php with php74
- bug fix while saving vhost conf
- address some security issues
- clear session files
- update path to execute php sessions
- prevent bypass of lsit check
- bug fix that causes upgrade to stuck
- Adding IPv6 listeners
- bug fix: pdns
- bug fix: email debugger
- bug fix: use different lscpd versions according to os detection
v2.3.2 Stable - Security Release
Dated: 27th June 2022
I am happy to announce that CyberPanel v2.3.2 has been released. This update brings tons of features and bug fixes to CyberPanel.
Right now CyberPanel is the only free control panel that is fully audited by RACK911 Labs for any security issues, team from RACK911 Labs is known for fixing security issues in web hosting industry. Apart from that we’ve brought some new features too:
- CyberPanel WordPress Manager
- Replace Rainloop with SnappyMail.
- New and improve PHP Extensions Manager
Bug Fixes
- bug fix: remote backup and backup restore
- Remove screenshots from Websites
- Remove screenshots from Child Domains
- bug fix: email configurations reset
- bug fix: email debugger on almalinux
- bug fix: email debugger for rockylinux
- Security: bug fix: change path of bwmeta
- bug fix in root fm
- bug fix in list dns
- bug fix: upgrade static content
- resolve alma issue, ref #891
- bug fix: subdomain creation on cent/alma
- bug fix: ssl obtain for childdomain on lsws ent
v2.3.1 Stable - Security Release
Dated: 25th April 2022
I am happy to announce that CyberPanel v2.3.1 has been released. This update brings tons of security and bug fixes to CyberPanel.
During this time we’ve also launched our new site and new community forums.
Right now CyberPanel is the only free control panel that is fully audited by RACK911 Labs for any security issues, team from RACK911 Labs is known for fixing security issues in web hosting industry. Apart from that we’ve brought some new features too:
- You will now be able to see weather you are on latest commit from Version Management in CyberPanel
- Root Level File Manager (Paid Feature)
- Google Drive Backups Retention (Paid Feature)
- Make Mautic 4.1.2 as default during installation
We’ve worked really hard so that you can use CyberPanel in mult-user environment with peace of mind.
Security Fixes
Please update your CyberPanel to v2.3.1 as soon as possible.
- security fix: CP-01: Installation improper permissions
- CP-05: Command Line Tools Type Insecure Processes Risk Medium
- CP-10: Admin – Websites – Suspend / Unsuspend
- CP-11: Admin – Packages – Delete Package
- CP-12: Admin – Packages – Modify Package
- CP-13: Admin – Back Up – Create Back Up
- CP-14: Admin – Back Up – Create Back Up
- CP-16: Admin Back Up Start Transfer
- security fix: CP-17: Admin – Security – CSF
- security fix: CP-18: Users – Create New User
- security fix: CP-21: Websites – Create Website
- security fix: CP-22: Websites – Modify Website
- security fix: CP-24: Manage Website – Domain Alias (Delete)
- security fix: CP-26: Manage Website – File Manager – Upload
- Security: Prevent leaking load average dat
- Security: PyYAML dependency update
- Security: Multiple CVE dependency update
- resolve CyberPanel 2.1 - Remote Code Execution (RCE) (Authenticated) - Multiple webapps Exploit
- securify fix: CP-29: Manage Website – SMTP Hosts – Verify
- securityfix: CP-30: Manage Website – Compose
- security fix: CP-33: Manage Website – Git
- security fix: CP-36: DNS – Add / Delete Records
- bug fix: CP-17
- CP-19: Additional Domains to Block
- CP-21: Additional Security
- Fix CVE-2021-32839
Bug Fixes
- bug fix: avoid possible removal of directories
- install acme.sh before main installation
- Update cyberpanel.sh
- bug fix: install
- bug fix: cronjob
- bug fix in backup creation
- bug fix: wp staging
- bug fix: custom ssl save
- bug fix: deploy staging to production
- bug fix: create wp staging
- security fix: CP-19: Websites – Create Website
- bug fix: fetch status
- bug fix: file manager
- bug fix: dkim manager
- Fix architecture detection
- add vhost level cache root for openlitespeed
- bug fix: continue backups if website is deleted from main CP
- bug fix: during website creation
- bug fix: backup creation
- use website level user for restic backups
- bug fix: incremental backups
- disable sftp destination for incremental backups for time being
- bug fix: delete database during inc backups
- bug fix: see git file changes
- bug fix: child domain records
- fix: file creation user
- bug fix: ssl
- bug fix: cpanel importer
- add confirm before converting to LiteSpeed Enterprise
- remove not needed function calls
v2.1.2 Stable - Security Release
Dated: 21st October 2021
This version does not introduce many front-end features. However we got audited by rack911labs and we did many changes to improve the security and make CyberPanel best, free and most secure control panel.
Features
- Ability to design CyberPanel user front-end design manager.
- Re-arrange some menu items
- Add option to switch to master again
- add bubblewrap default command
- Added translation tag for some elements
- Add table for dashboad css
- Load custom css
- More verbose logs
- Add logging
- Fix architecture detection
- Add vhost level cache root for openlitespeed
- Add further detect for rocky
- Zero ssl account registration
Bug fixes:
- Add Litespeed/OLS admin port to default allowed
- PHPMyAdmin autologin upon document ready
- Elastic search install
- Updated restic installer for Centos7/8
- cPanel importer set default php if the inherit php is not set
- Fix a bug in mailwatch sql file
- Email configs reset
- Email debugger
- Incremental backups
- Incremental backups delete
- Remove backup and meta directories from incremental backups
- Remove mount tmp
- Bring back mount tmp
- Some design issues
- Mail reset ubuntu 20
- Email reset fix for ubuntu 18
- Remove comodo rules packs
- Fix enable/disable for updated rules files
- Added support for LiteSpeed Ent for OWASP and updated the rules, ref
- Host selection in remote host;
- Fixed a bug that cause restore fail if 1 user have access to more the
- Bug fix in backup creation of complete website
- Resolve bug in modsec rules
- Watchdog updated to include Dovecot, Postfix, PowerDNS, and Pure-FTPd
- Fixed watchdog PowerDNS service name.
- Refactored watchdog to be easier to add additional services.
- Security fix: CP-10: Admin Websites Suspend / Unsuspend
- Security fix: CP-11: Admin Packages Delete Package
- Security fix: CP-12: CP-12: Admin Packages Modify Package
- Security fix: CP-13: Admin Back Up Create Back Up
- Security fix in backups
- Security fix: CP-13: Admin Back Up Create Back Up
- CP-14: Admin Back Up Create Back Up
- CP-16: Admin Back Up Start Transfer
- Security fix: CP-17: Admin – Security – CSF
- Security fix: CP-18: Users – Create New User
- Avoid possible removal of directories
- Security fix: CP-21: Websites – Create Website
- Security fix: CP-22: Websites – Modify Website
- Security fix: CP-24: Manage Website – Domain Alias (Delete)
- Security fix: CP-26: Manage Website – File Manager – Upload
- Security: Prevent leaking load average data
- Security: PyYAML dependency update
- Security: Multiple CVE dependency update
- Dependency fix
- Install
- Securify fix: CP-29: Manage Website – SMTP Hosts – Verify
- Securityfix: CP-30: Manage Website – Compose
- Security fix: CP-33: Manage Website – Git
- Security fix: CP-36: DNS – Add / Delete Records
- Bug fix: cron jobs
- Fix in backup creation
- Update some permissions
- Wp staging
- Custom ssl save
- Deploy staging to production
- Create wp staging
- Security fix: CP-19: Websites – Create Website
- Fetch status
- File manager
- Dkim manager
- Bug fix: CP-17
- CP-19: Additional Domains to Block
- CP-21: Additional Security
- Fix wp staging
- Continue backups if website is deleted from main CP
- Postfix disable VRFY
- Simplify getPHPString() & update php version for mail domain
- Update issue templates
- During website creation
- Follow PEP 8 style guide
v2.1.1 Stable
Dated: 15th April 2021
Features
- Joomla installer: auto-install with LS cache
- Codemirror added to file manager (multiple language support )
- Allow users to manage SSH keys
- Initiate cloudbackup ( via CyberPanel Cloud ), Cloud backups to AWS, Restore s3 backups
- Add PHP 8.0
- WP deploy ( via Cloud )
- WP manager ( Cloud )
- Proprietary High Availability
- Add search and ordering to dropdowns
- Re-renders for all UI elements
- DigitalOcean remote DB support
- NEW installer script
- NEW upgrade script
- Enforce disk limits via packages.
- Support for multiple database users in backups
Bug Fixes
- Bug fix in backup up websites restored via cPanel importer
- Bug fix for setting up remote access to databases.
- Fixing Mautic Installer link and title.
- Redis installation on Centos 8
- Restart backup if killed prematurely, bypass the stuck domain
- Remove systemd-resolvd on CentOS 8
- Postfix files during upgrade
- Remove default modsec rules in LSWS config
- Cloudlinux Reseller
- Imunify360 access URL
- Disk/bandwidth usage to calculate every 12 hour
- Sub folder WP installations
- Add website owner email for vhost SSL config
- Centralize ACL control
- Cater remote DB during staging deployment
- Database deletion
- Child domain deletion including directories
- Major bug fixes in cPanel importer to find all paths for domains