Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Primekey

First CVE: Apr 8, 2020Active for: 6 yearsTotal CVEs: 17
13.8
VTI Score
Low

Primekey develops a narrow portfolio of public-key infrastructure and code-signing platforms, with EJBCA and SignServer as the core products deployed across enterprise certificate management and digital signature workloads. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through weakness classes including improper certificate validation, cross-site scripting, cleartext storage of sensitive information, and cross-site request forgery, reflecting the authentication and trust-management surface inherent to PKI software. Defenders should treat this vendor's advisories as high-priority given the critical role these platforms play in issuing and validating credentials; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Primekey over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2020
6 years ago
Most Recent CVE
Mar 31, 2025
480 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-34831CRITICAL
An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submit
Sep 14, 20229.829NONO
CVE-2020-11630CRITICAL
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the P
Apr 8, 20209.829NONO
CVE-2020-11627HIGH
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.
Apr 8, 20208.826NONO
CVE-2020-25276HIGH
An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certif
Sep 11, 20207.322NONO
CVE-2025-3027MEDIUM
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the req
Mar 31, 20256.119NONO
CVE-2022-40711MEDIUM
PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users.
Jan 1, 20234.819NONO
CVE-2022-26494MEDIUM
An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administr
Mar 21, 20224.819NONO
CVE-2021-40088MEDIUM
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certif
Aug 25, 20215.419NONO
CVE-2020-11629HIGH
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to valid
Apr 8, 20207.219NONO
CVE-2025-3026MEDIUM
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulat
Mar 31, 20256.118NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
18%
53%
18%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.9%)
Network16 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (94.1%)
High1 (5.9%)
Unknown0 (0.0%)
User Interaction
None11 (64.7%)
Unknown0 (0.0%)
Required6 (35.3%)
Privileges Required
Low3 (17.6%)
High6 (35.3%)
None8 (47.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Primekey.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Primekey — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Primekey's Products

View all 2 CNAs →

Top CWEs