Known Vulnerabilities for Method-override by Expressjs
Listed below are 1 of the newest known vulnerabilities associated with "Method-override" by "Expressjs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-91819 json | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-85630 json | HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attr... | Not Provided | 2026-09-08 | 2026-09-10 |
| CVE-2026-85484 json | HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without esca... | Not Provided | 2026-09-08 | 2026-09-10 |
| CVE-2026-78683 json | NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParse... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-49099 json | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Thro... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-47198 json | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the chec... | Not Provided | 2026-07-20 | 2026-07-22 |
| CVE-2026-37236 json | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header i... | Not Provided | 2026-08-28 | 2026-09-02 |
| CVE-2026-15988 json | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forg... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2017-16136 json | method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where ... | 7.5 - HIGH | 2018-06-07 | 2019-10-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Expressjs | Method-override | 3.0.0 | |||
| Application | Expressjs | Method-override | 2.3.9 | |||
| Application | Expressjs | Method-override | 2.3.8 | |||
| Application | Expressjs | Method-override | 2.3.7 | |||
| Application | Expressjs | Method-override | 2.3.6 | |||
| Application | Expressjs | Method-override | 2.3.5 | |||
| Application | Expressjs | Method-override | 2.3.4 | |||
| Application | Expressjs | Method-override | 2.3.3 | |||
| Application | Expressjs | Method-override | 2.3.2 | |||
| Application | Expressjs | Method-override | 2.3.10 | |||
| Application | Expressjs | Method-override | 2.3.1 | |||
| Application | Expressjs | Method-override | 2.3.0 | |||
| Application | Expressjs | Method-override | 2.2.0 | |||
| Application | Expressjs | Method-override | 2.1.3 | |||
| Application | Expressjs | Method-override | 2.1.2 | |||
| Application | Expressjs | Method-override | 2.1.1 | |||
| Application | Expressjs | Method-override | 2.1.0 | |||
| Application | Expressjs | Method-override | 2.0.2 | |||
| Application | Expressjs | Method-override | 2.0.1 | |||
| Application | Expressjs | Method-override | 2.0.0 |