Ascertia's vulnerability footprint centers on SigningHub, a digital signing and document management platform deployed across enterprise environments for legally binding transaction workflows. Vulnerabilities affecting the vendor skew strongly toward critical severity outcomes and recur through weakness classes including resource-exhaustion conditions, brute-force and rate-limiting bypasses, access-control failures, and open-redirect flaws that are characteristic of web applications handling sensitive authentication and document flows. Defenders should prioritize patches for this vendor given the severity tendency and the critical role its products play in transaction integrity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ascertia over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56218CRITICAL An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file. | Oct 17, 2025 | 9.8 | 37 | NO | NO |
CVE-2025-54321CRITICAL In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can expl | Nov 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-56221CRITICAL A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack. | Oct 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-56224HIGH A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack. | Oct 20, 2025 | 8.1 | 29 | NO | NO |
CVE-2025-56223HIGH A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of fi | Oct 20, 2025 | 7.5 | 28 | NO | NO |
CVE-2025-56219HIGH Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Se | Oct 20, 2025 | 7.1 | 26 | NO | NO |
CVE-2025-61166MEDIUM An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL. | Apr 6, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-54320MEDIUM In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit | Nov 18, 2025 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ascertia.
Media articles that mention a CVE ID that affects a product developed by Ascertia — matched by CVE ID, not by vendor name.