← Vulnerability feed

Vulnerability record · CVE-2021-37627 · published 11 August 2021

CVE-2021-37627: Contao improper privilege management vulnerability

Contao · Contao

Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form generator or disable the login for untrusted back end users.

7.2 CVSS 3.1 High EPSS 1.0% · top 37.9% CWE-269 · Improper privilege management
7.2CVSS 3.1 base score, v2 6.5
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is possible to gain privileged rights in the Contao back end. Installations are only affected if they have untrusted back end users who have access to the form generator. All users are advised to update to Contao 4.4.56, 4.9.18 or 4.11.7. As a workaround users may disable the form generator or disable the login for untrusted back end users.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-37627 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26265Contao os command injection vulnerabilityContao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component php_cli parameter.EPSS 30%9.8CVE-2019-11512Contao sql injection vulnerabilityContao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.EPSS 1.5%8.8CVE-2024-45398Contao unrestricted file upload vulnerabilityContao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the…EPSS 0.53%8.8CVE-2012-4383Contao sql injection vulnerabilitycontao prior to 2.11.4 has a sql injection vulnerabilityEPSS 0.92%8.8CVE-2019-19745Contao unrestricted file upload vulnerabilityContao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute th…EPSS 1.1%7.2CVE-2021-37626Contao code injection vulnerabilityContao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files …EPSS 1.3%7.1CVE-2024-30262Contao insufficient session expiration vulnerabilityContao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or t…EPSS 0.50%6.6CVE-2025-65960Contao vulnerabilityContao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the con…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2021-37627), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.