I'd like to upload some flags in SVG format, but I get this message whenever I try to:
I understand XSS is a concern, but even if you don't want to go through the trouble of setting up an SVG sanitizer, there are ways of mitigating the risk:
https://github.com/digininja/svg_xss