VendorsErudikascooldall versions
Vulnerabilities

Erudika Scoold

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-1543
Improper handling of Length parameter in erudika/scoold
Published 2022-04-29 · Modified
9.3EPSS 0.011
CVE-2024-50334
Semicolon Path Injection on API /api;/config
Published 2024-10-29 · Analyzed
8.7EPSS 0.010
CVE-2026-34832
Scoold: Cross-Account Feedback Deletion (IDOR)
Published 2026-04-02 · Analyzed
6.5EPSS 0.005
CVE-2026-39354
Scoold has an Authenticated Arbitrary Question Overwrite via Client-Controlled postId in POST /questions/ask
Published 2026-04-07 · Analyzed
6.5EPSS 0.003
CVE-2021-46372
Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters.
Published 2022-02-18 · Modified
5.4EPSS 0.006