Acc develops a narrowly scoped portfolio centered on content management and collaboration platforms, including its DM Corporative CMS and Tigris products, that handle sensitive organizational data and user access control. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes including authorization bypass, SQL injection, and information exposure, reflecting the authentication and data-handling demands of web-based content platforms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acc over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40654CRITICAL A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name and cod | Jun 10, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-40657CRITICAL A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the codform param | Jun 10, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-40656CRITICAL A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the cod parameter | Jun 10, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-40655CRITICAL A SQL injection vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to retrieve, create, update and delete databases through the name paramete | Jun 10, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-40658HIGH An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option p | Jun 10, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-40660HIGH An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option p | Jun 10, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-40659HIGH An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option p | Jun 10, 2025 | 7.5 | 20 | NO | NO |
CVE-2025-40662HIGH Absolute path disclosure vulnerability in DM Corporative CMS. This vulnerability allows an attacker to view the contents of webroot/file, if navigating to a non-existent file. | Jun 10, 2025 | 7.5 | 19 | NO | NO |
CVE-2025-40661HIGH An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option p | Jun 10, 2025 | 7.5 | 19 | NO | NO |
CVE-1999-0383HIGH ACC Tigris allows public access without a login. | Feb 2, 1999 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acc.
Media articles that mention a CVE ID that affects a product developed by Acc — matched by CVE ID, not by vendor name.