---
id: CVE-2026-102290
title: A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2
summary: >-
  A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This
  affects an unknown function of the component Student Profile Image Upload.
  Executing a manipulation can lead to cross site scripting. The attack can be
  executed remo…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: CodeCanyon
product: Rocket LMS
affected:
  - rocket_lms 2.0
  - rocket_lms 2.1
  - rocket_lms 2.2
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T05:16:59.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102290'
references:
  - url: >-
      https://drive.google.com/file/d/1kICrUOCzmXgf2iW1qEX8q9jW_R3twEBb/view?usp=sharing
    label: cna@vuldb.com
  - url: >-
      https://gist.github.com/MuhammadAmmar-Hacker/05f13a39b35ae3dc31d86a5b919b5e2a
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-102290'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/939876'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411167'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/411167/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T05:28:04.815Z'
---

## Overview

A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Student Profile Image Upload. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
