Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ascertia

First CVE: Oct 17, 2025Active for: 1 yearTotal CVEs: 8

Ascertia's vulnerability footprint centers on SigningHub, a digital signing and document management platform deployed across enterprise environments for legally binding transaction workflows. Vulnerabilities affecting the vendor skew strongly toward critical severity outcomes and recur through weakness classes including resource-exhaustion conditions, brute-force and rate-limiting bypasses, access-control failures, and open-redirect flaws that are characteristic of web applications handling sensitive authentication and document flows. Defenders should prioritize patches for this vendor given the severity tendency and the critical role its products play in transaction integrity; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ascertia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 17, 2025
9 months ago
Most Recent CVE
Apr 6, 2026
109 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-56218CRITICAL
An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
Oct 17, 20259.837NONO
CVE-2025-54321CRITICAL
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can expl
Nov 18, 20259.834NONO
CVE-2025-56221CRITICAL
A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.
Oct 17, 20259.834NONO
CVE-2025-56224HIGH
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
Oct 20, 20258.129NONO
CVE-2025-56223HIGH
A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of fi
Oct 20, 20257.528NONO
CVE-2025-56219HIGH
Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Se
Oct 20, 20257.126NONO
CVE-2025-61166MEDIUM
An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.
Apr 6, 20266.121NONO
CVE-2025-54320MEDIUM
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit
Nov 18, 20254.317NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
25%
38%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None6 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ascertia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ascertia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ascertia's Products

View all 1 CNAs →

Top CWEs