Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Accela

First CVE: Jul 15, 2016Active for: 10 yearsTotal CVEs: 6

Accela provides a focused suite of government and civic-process software platforms, including its Civic Platform and Automation Platform products, which handle permitting, licensing, and citizen-facing service delivery for municipalities and agencies. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring exposure centers on web application weaknesses—cross-site scripting, code injection, path traversal, and improper access control—that arise from the platforms' role in handling citizen requests and government data. Defenders managing Accela deployments should prioritize patching for internet-exposed instances and review access controls around sensitive permit and licensing workflows; current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Accela over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 15, 2016
10 years ago
Most Recent CVE
Sep 19, 2025
308 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-34370MEDIUM
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are configurable security flags and we are unable to reproduce t
Jun 9, 20216.142NOYES
CVE-2021-33904MEDIUM
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The vendor states "there are configurable security flags and we
Jun 7, 20216.142NOYES
CVE-2021-34369MEDIUM
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensitive information via a modified contactSeqNumber value. NOTE:
Jun 9, 20216.534NOYES
CVE-2025-57644CRITICAL
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the
Sep 19, 20259.132NONO
CVE-2016-5661HIGH
Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified
Jul 15, 20168.822NONO
CVE-2016-5660MEDIUM
Cross-site scripting (XSS) vulnerability in AttachmentsList.aspx in Accela Civic Platform Citizen Access portal allows remote attackers to inject arbitrary web script or HTML via t
Jul 15, 20166.117NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
67%
17%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low2 (33.3%)
High1 (16.7%)
None3 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
33.3% of CVEs· 98th percentile
ExploitDB
3 CVEs
50.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Accela.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Accela — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Accela's Products

View all 2 CNAs →

Top CWEs