Codecanyon · Rocket Lms · CVE-2026-102290
**Name of the Vulnerable Software and Affected Versions**
CodeCanyon Rocket LMS versions prior to 2.3
**Description**
An issue exists in the Student Profile Image Upload component where a remote manipulation can lead to cross site scripting (XSS), a technique used to inject malicious scripts into web pages viewed by other users.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.