Primekey develops a narrow portfolio of public-key infrastructure and code-signing platforms, with EJBCA and SignServer as the core products deployed across enterprise certificate management and digital signature workloads. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through weakness classes including improper certificate validation, cross-site scripting, cleartext storage of sensitive information, and cross-site request forgery, reflecting the authentication and trust-management surface inherent to PKI software. Defenders should treat this vendor's advisories as high-priority given the critical role these platforms play in issuing and validating credentials; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Primekey over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34831CRITICAL An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submit | Sep 14, 2022 | 9.8 | 29 | NO | NO |
CVE-2020-11630CRITICAL An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the P | Apr 8, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-11627HIGH An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI. | Apr 8, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-25276HIGH An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certif | Sep 11, 2020 | 7.3 | 22 | NO | NO |
CVE-2025-3027MEDIUM The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the req | Mar 31, 2025 | 6.1 | 19 | NO | NO |
CVE-2022-40711MEDIUM PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users. | Jan 1, 2023 | 4.8 | 19 | NO | NO |
CVE-2022-26494MEDIUM An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administr | Mar 21, 2022 | 4.8 | 19 | NO | NO |
CVE-2021-40088MEDIUM An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certif | Aug 25, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-11629HIGH An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to valid | Apr 8, 2020 | 7.2 | 19 | NO | NO |
CVE-2025-3026MEDIUM The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulat | Mar 31, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Primekey.
Media articles that mention a CVE ID that affects a product developed by Primekey — matched by CVE ID, not by vendor name.