Ejbca
Vendor:
First CVE: Apr 8, 2020 · Active for 6 years
16
Total CVEs
More Total CVEs than 92% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ejbca over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2020
6 years ago
Most Recent CVE
Mar 31, 2025
480 days ago
CVE Severity & Scoring
Ejbca16 CVEs
19%
50%
19%
13%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (6.3%)
Network15 (93.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High1 (6.3%)
Unknown0 (0.0%)
User Interaction
None11 (68.8%)
Unknown0 (0.0%)
Required5 (31.3%)
Privileges Required
Low3 (18.8%)
High5 (31.3%)
None8 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34831CRITICAL An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submit | Sep 14, 2022 | 9.8 | 29 | NO | NO |
CVE-2020-11630CRITICAL An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the P | Apr 8, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-11627HIGH An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. A Cross Site Request Forgery (CSRF) issue has been found in the CA UI. | Apr 8, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-25276HIGH An issue was discovered in PrimeKey EJBCA 6.x and 7.x before 7.4.1. When using a client certificate to enroll over the EST protocol, no revocation check is performed on that certif | Sep 11, 2020 | 7.3 | 22 | NO | NO |
CVE-2025-3027MEDIUM The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the req | Mar 31, 2025 | 6.1 | 19 | NO | NO |
CVE-2022-40711MEDIUM PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users. | Jan 1, 2023 | 4.8 | 19 | NO | NO |
CVE-2021-40088MEDIUM An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certif | Aug 25, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-11629HIGH An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. The External Command Certificate Validator, which allows administrators to upload external linters to valid | Apr 8, 2020 | 7.2 | 19 | NO | NO |
CVE-2025-3026MEDIUM The vulnerability exists in the EJBCA service, version 8.0 Enterprise. Not tested in higher versions. By modifying the ‘Host’ header in an HTTP request, it is possible to manipulat | Mar 31, 2025 | 6.1 | 18 | NO | NO |
CVE-2020-11631MEDIUM An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. An error state can be generated in the CA UI by a malicious user. This, in turn, allows exploitation of oth | Apr 8, 2020 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Ejbca
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.9.0.2 | 1 | 4.8 | 0.5% | 0 | 0 |