Ascertia Signinghub vulnerabilities
8 known vulnerabilities affecting ascertia/signinghub.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-56218P2CRITICALCVSS 9.8≤ 8.6.82025-10-17
CVE-2025-56218 [CRITICAL] CWE-434 CVE-2025-56218: An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary co
An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
nvd
CVE-2025-54321P2CRITICALCVSS 9.8≤ 8.6.82025-11-18
CVE-2025-54321 [CRITICAL] CWE-799 CVE-2025-54321: In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password functio
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.
nvd
CVE-2025-56221P3CRITICALCVSS 9.8≤ 8.6.82025-10-17
CVE-2025-56221 [CRITICAL] CWE-307 CVE-2025-56221: A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authe
A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brute force attack.
nvd
CVE-2025-56224P3HIGHCVSS 8.1≤ 8.6.82025-10-20
CVE-2025-56224 [HIGH] CWE-307 CVE-2025-56224: A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 al
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
nvd
CVE-2025-56223P3HIGHCVSS 7.5≤ 8.6.82025-10-20
CVE-2025-56223 [HIGH] CWE-770 CVE-2025-56223: A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows atta
A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.
nvd
CVE-2025-56219P4HIGHCVSS 7.1≤ 8.6.82025-10-20
CVE-2025-56219 [HIGH] CWE-284 CVE-2025-56219: Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts with
Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user accounts are created.
nvd
CVE-2025-54320P4MEDIUMCVSS 4.3≤ 8.6.82025-11-18
CVE-2025-54320 [MEDIUM] CWE-770 CVE-2025-54320: In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function,
In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating invite requests.
nvd
CVE-2025-61166P4MEDIUMCVSS 6.1v8.6.8v10.02026-04-06
CVE-2025-61166 [MEDIUM] CWE-601 CVE-2025-61166: An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious
An open redirect in Ascertia SigningHub User v10.0 allows attackers to redirect users to a malicious site via a crafted URL.
nvd