Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Keyfactor

First CVE: Nov 17, 2022Active for: 4 yearsTotal CVEs: 10
17.0
VTI Score
Low

Keyfactor develops certificate and key management infrastructure software, including products such as SignServer, EJBCA, and cloud-orchestration tools that sit at the trust boundary of public-key systems. Its vulnerability profile centers on access-control weaknesses, input-validation flaws, and sensitive-data exposure issues typical of authentication and certificate-issuance platforms where improper controls can cascade across dependent systems. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Keyfactor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2022
3 years ago
Most Recent CVE
Dec 22, 2025
214 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-47222MEDIUM
A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided c
Nov 13, 20256.522NONO
CVE-2023-34196HIGH
In the Keyfactor EJBCA before 8.0.0, the RA web certificate distribution servlet /ejbca/ra/cert allows partial denial of service due to an authentication issue. In configurations u
Aug 3, 20238.222NONO
CVE-2022-39834MEDIUM
A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher
Nov 17, 20225.421NONO
CVE-2024-42006HIGH
Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.
Aug 20, 20247.520NONO
CVE-2024-34458HIGH
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.
Aug 20, 20247.520NONO
CVE-2022-42954MEDIUM
Keyfactor EJBCA before 7.10.0 allows XSS.
Nov 17, 20225.420NONO
CVE-2025-26787MEDIUM
An error in the SignServer container startup logic was found in Keyfactor SignServer versions prior to 7.2. The Admin CLI command used to configure Certificate access to the initia
Dec 22, 20254.719NONO
CVE-2025-47221MEDIUM
An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTER
Nov 13, 20255.319NONO
CVE-2025-47220MEDIUM
A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in the PDFSigner and the PAdESSig
Nov 13, 20255.319NONO
CVE-2024-36066LOW
The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle
Sep 12, 20243.114NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
60%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low3 (30.0%)
High1 (10.0%)
None6 (60.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Keyfactor.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Keyfactor — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Keyfactor's Products

View all 1 CNAs →

Top CWEs