Aggregates CVE and security vulnerability intelligence across all erudika-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk cross-site scripting and vendor risk memory corruption; exposure may include vendor impact session compromise in vendor surface software deployment contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-39354 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-privilege user to overwrite another user's existing question by supplying that question's public ID as the postId parameter to POST /questions/ask. Because question IDs are exposed in normal question URLs, a low-privilege attacker can take a victim question ID from a public page and cause attacker-controlled content to be stored under that existing | [email protected] | 6.5 | 0.03% | 2026-04-07 | 2026-04-10 |
| CVE-2026-34832 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged-in, low-privilege user to delete another user's feedback post by submitting its ID to POST /feedback/{id}/delete. The handler enforces authentication but does not enforce object ownership (or moderator/admin authorization) before deletion. In verification, a second non-privileged account successfully deleted a victim | [email protected] | 6.5 | 0.09% | 2026-04-02 | 2026-04-15 |
| CVE-2024-50334 | Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive configuration data. Furthermore, PUT requests on the /api;/config endpoint while setting the Content-Type: application/hocon header allow unauthenticated attackers to file reading via HOCON file inclusion. This allows attackers to retrieve sens | [email protected] | 8.7 | 10.11% | 2024-10-29 | 2024-11-08 |
| CVE-2022-1848 | Business Logic Errors in GitHub repository erudika/para prior to 1.45.11. | [email protected] | 5.3 | 0.36% | 2022-05-24 | 2024-11-21 |
| CVE-2022-1782 | Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11. | [email protected] | 6.1 | 0.30% | 2022-05-18 | 2024-11-21 |
| CVE-2022-1543 | Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server. | [email protected] | 8.8 | 0.41% | 2022-04-29 | 2024-11-21 |
| CVE-2021-46372 | Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters. | [email protected] | 5.4 | 0.19% | 2022-02-18 | 2024-11-21 |