Keyfactor develops certificate and key management infrastructure software, including products such as SignServer, EJBCA, and cloud-orchestration tools that sit at the trust boundary of public-key systems. Its vulnerability profile centers on access-control weaknesses, input-validation flaws, and sensitive-data exposure issues typical of authentication and certificate-issuance platforms where improper controls can cascade across dependent systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keyfactor over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47222MEDIUM A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided c | Nov 13, 2025 | 6.5 | 22 | NO | NO |
CVE-2023-34196HIGH In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations u | Aug 3, 2023 | 8.2 | 22 | NO | NO |
CVE-2022-39834MEDIUM A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher | Nov 17, 2022 | 5.4 | 21 | NO | NO |
CVE-2024-42006HIGH Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure. | Aug 20, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-34458HIGH Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure. | Aug 20, 2024 | 7.5 | 20 | NO | NO |
CVE-2022-42954MEDIUM Keyfactor EJBCA before 7.10.0 allows XSS. | Nov 17, 2022 | 5.4 | 20 | NO | NO |
CVE-2025-26787MEDIUM An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initia | Dec 22, 2025 | 4.7 | 19 | NO | NO |
CVE-2025-47221MEDIUM An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTER | Nov 13, 2025 | 5.3 | 19 | NO | NO |
CVE-2025-47220MEDIUM A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in the PDFSigner and the PAdESSig | Nov 13, 2025 | 5.3 | 19 | NO | NO |
The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle | Sep 12, 2024 | 3.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keyfactor.
Media articles that mention a CVE ID that affects a product developed by Keyfactor — matched by CVE ID, not by vendor name.