CVE-2026-102290 | CodeCanyon Rocket LMS up to 2.2 Student Profile Image Upload cross site scripting

SecurityVulns

A vulnerability classified as problematic was found in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scripting.

This vulnerability is handled as CVE-2026-102290. The attack can be executed remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More