Erudika maintains a focused product line centered on the community Q&A platform Scoold and the Para backend-as-a-service framework, both oriented toward knowledge-sharing and social application infrastructure. The vendor's vulnerability profile reflects typical exposure for web-facing applications, recurring through authorization and authentication bypass weaknesses, cross-site scripting, and input-handling issues, and frequently acquires public exploit code. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Erudika over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50334MEDIUM Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, at | Oct 29, 2024 | 5.3 | 28 | NO | YES |
CVE-2022-1543HIGH Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a product | Apr 29, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-39354MEDIUM Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-privilege user to overwrite ano | Apr 7, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-34832MEDIUM Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged | Apr 2, 2026 | 6.5 | 22 | NO | NO |
CVE-2021-46372MEDIUM Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters. | Feb 18, 2022 | 5.4 | 19 | NO | NO |
CVE-2022-1848MEDIUM Business Logic Errors in GitHub repository erudika/para prior to 1.45.11. | May 24, 2022 | 5.3 | 17 | NO | NO |
CVE-2022-1782MEDIUM Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11. | May 18, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Erudika.
Media articles that mention a CVE ID that affects a product developed by Erudika — matched by CVE ID, not by vendor name.