Mhonarc is a mail-to-HTML archiving utility deployed across mailing-list hosting and email-archive infrastructure, where its primary exposure centers on the product's web-output generation layer. The observed vulnerability pattern reflects input-handling issues in HTML conversion, particularly cross-site scripting conditions arising from the processing of email content into web-accessible archives. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mhonarc over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1307MEDIUM Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML via an email message with the script in a MIME header name. | Nov 29, 2002 | 6.8 | 33 | NO | YES |
CVE-2010-1677MEDIUM MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed within other start tags, as demonstrated by a <bo<bo<bo<bo<body | Jan 3, 2011 | 5.0 | 30 | NO | YES |
CVE-2002-0738HIGH MHonArc 2.5.2 and earlier does not properly filter Javascript from archived e-mail messages, which could allow remote attackers to execute script in web clients by (1) splitting th | Aug 12, 2002 | 7.5 | 25 | NO | NO |
CVE-2010-4524MEDIUM Cross-site scripting (XSS) vulnerability in lib/mhtxthtml.pl in MHonArc 2.6.16 allows remote attackers to inject arbitrary web script or HTML via a malformed start tag and end tag | Jan 3, 2011 | 4.3 | 17 | NO | NO |
CVE-2002-1388MEDIUM Cross-site scripting (XSS) vulnerability in MHonArc before 2.5.14 allows remote attackers to inject arbitrary HTML into web archive pages via HTML mail messages. | Jan 2, 2003 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mhonarc.
Media articles that mention a CVE ID that affects a product developed by Mhonarc — matched by CVE ID, not by vendor name.