CVE-2023-53876: Creativeitem Academy Lms
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.
Affected products
- Creativeitem Academy Lms: version 6.1 only
Published 2025-12-15. Last modified 2026-06-17.