« Back to list

Ascertia

Ascertia Signinghub: vulnerabilities and CVEs

Ascertia Signinghub has 8 published vulnerabilities, 8 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months8
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-61166Medium (6.1)0.18%—Apr 6, 2026
An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.
CVE-2025-54321Critical (9.8)0.47%—Nov 18, 2025
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password…
CVE-2025-54320Medium (4.3)0.33%—Nov 18, 2025
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.
CVE-2025-56224High (8.1)0.39%—Oct 20, 2025
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
CVE-2025-56223High (7.5)0.46%—Oct 20, 2025
A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.
CVE-2025-56219High (7.1)0.32%—Oct 20, 2025
Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large…
CVE-2025-56221Critical (9.8)0.60%—Oct 17, 2025
A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.
CVE-2025-56218Critical (9.8)0.63%—Oct 17, 2025
An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application5
  2. T1078.001 Default Accounts2
  3. T1499.004 Application or System Exploitation2
  4. T1210 Exploitation of Remote Services1
  5. T1505.003 Web Shell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.