Ejbca

Vendor:

First CVE: Apr 8, 2020 · Active for 6 years

16
Total CVEs
More Total CVEs than 92% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ejbca over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2020
6 years ago
Most Recent CVE
Mar 31, 2025
480 days ago

CVE Severity & Scoring

Ejbca16 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None11 (68.8%)
Unknown0 (0.0%)
Required5 (31.3%)
Privileges Required
Low3 (18.8%)
High5 (31.3%)
None8 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submit
Sep 14, 20229.829NONO
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the P
Apr 8, 20209.829NONO
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI.
Apr 8, 20208.826NONO
An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certif
Sep 11, 20207.322NONO
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the req
Mar 31, 20256.119NONO
PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users.
Jan 1, 20234.819NONO
An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certif
Aug 25, 20215.419NONO
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to valid
Apr 8, 20207.219NONO
The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulat
Mar 31, 20256.118NONO
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of oth
Apr 8, 20206.517NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Ejbca

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.9.0.214.80.5%00