← Vulnerability feed

Vulnerability record · CVE-2023-36138 · published 4 August 2023

CVE-2023-36138: Phpjabbers cleaning business software cross-site scripting vulnerability

Phpjabbers · Cleaning Business Software

PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.

6.1 CVSS 3.1 Medium EPSS 0.44% · top 63.9% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-36138 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-36140Phpjabbers cleaning business software missing authorization vulnerabilityIn PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.EPSS 0.53%9.8CVE-2023-36139Phpjabbers cleaning business software insufficient verification of data authenticity vulnerabilityIn PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote…EPSS 0.45%6.5CVE-2023-51326Phpjabbers cleaning business software authentication bypass by spoofing vulnerabilityA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount o…EPSS 0.47%6.5CVE-2023-51327Phpjabbers cleaning business software authentication bypass by spoofing vulnerabilityA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessive amount o…EPSS 0.47%6.5CVE-2023-51331Phpjabbers cleaning business software code injection vulnerabilityPHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerab…EPSS 0.51%6.1CVE-2023-4115Phpjabbers cleaning business software cross-site scripting vulnerabilityA vulnerability classified as problematic has been found in PHP Jabbers Cleaning Business 1.0. Affected is an unknown function of the file /index.php…EPSS 8.4%5.4CVE-2023-51328Phpjabbers cleaning business software cross-site scripting vulnerabilityPHPJabbers Cleaning Business Software v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "c_name, name" parameters.EPSS 0.38%5.3CVE-2023-36141Phpjabbers cleaning business software vulnerabilityUser enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2023-36138), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.