Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Facebook — Vulnerabilities & Security Advisories 144

Browse all 144 CVE security advisories affecting Facebook. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Facebook operates a global social networking platform facilitating user interaction, content sharing, and targeted advertising. With 140 recorded Common Vulnerabilities and Exposures (CVEs), its attack surface reflects the complexity of large-scale web infrastructure. Historically, the platform has been susceptible to cross-site scripting (XSS), which allows attackers to inject malicious scripts into web pages viewed by other users. Remote code execution (RCE) vulnerabilities have also appeared, potentially granting unauthorized access to underlying server systems. Additionally, privilege escalation flaws have enabled users to bypass intended access controls, accessing restricted data or features. Notable incidents include data breaches affecting millions of accounts and API misconfigurations that exposed private user information. These security challenges highlight the persistent risks associated with managing vast amounts of personal data and maintaining robust authentication mechanisms across a distributed network architecture.

CVE ID Title CVSS Severity Published
CVE-2026-66707 WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerability — Facebook for WooCommerce CWE-79 7.1 High 2026-08-06
CVE-2026-66705 WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerability — Facebook for WordPress CWE-79 7.1 High 2026-08-06
CVE-2026-44909 Facebook proxygen 资源管理错误漏洞 — proxygen 7.5 High 2026-07-23
CVE-2026-49059 WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnerability — Facebook for WooCommerce CWE-601 4.7 Medium 2026-05-27
CVE-2026-23866 Facebook WhatsApp 安全漏洞 — WhatsApp for Android 4.3 Medium 2026-05-01
CVE-2026-23863 Facebook WhatsApp 安全漏洞 — WhatsApp Desktop for Windows 6.5 Medium 2026-05-01
CVE-2025-55181 Facebook Proxygen 安全漏洞 — proxygen 5.3 Medium 2025-12-02
CVE-2025-55179 Facebook WhatsApp 安全漏洞 — WhatsApp Business for iOS 5.4 Medium 2025-11-18
CVE-2025-64296 WordPress Facebook for WooCommerce plugin <= 3.5.7 - Broken Access Control to Notice Dismissal vulnerability — Facebook for WooCommerce CWE-862 5.3 Medium 2025-10-29
CVE-2025-55177 Facebook WhatsApp 安全漏洞 — WhatsApp Desktop for Mac 5.4 Medium 2025-08-29
CVE-2025-30403 mvfst 安全漏洞 — mvfst 9.1AI Critical AI 2025-07-11
CVE-2025-30401 Facebook WhatsApp 安全漏洞 — WhatsApp Desktop for Windows 8.1AI High AI 2025-04-05
CVE-2020-36838 Facebook Chat Plugin <= 1.5 - Missing Capabilities Check — Facebook Chat Plugin – Live Chat Plugin for WordPress CWE-284 7.4 High 2024-10-16
CVE-2024-45863 Facebook Thrift 安全漏洞 — Facebook Thrift 9.8AI Critical AI 2024-09-27
CVE-2024-45773 Facebook Thrift 安全漏洞 — Facebook Thrift 9.8AI Critical AI 2024-09-27
CVE-2023-49062 Meta Katran 安全漏洞 — Katran 7.5 - 2023-11-28
CVE-2023-38538 WhatsApp 竞争条件问题漏洞 — WhatsApp Desktop for Mac 5.0 Medium 2023-10-04
CVE-2023-38537 WhatsApp 竞争条件问题漏洞 — WhatsApp Desktop for Mac 5.6 Medium 2023-10-04
CVE-2023-30470 Facebook Hermes 资源管理错误漏洞 — Hermes 9.8 - 2023-05-18
CVE-2023-28753 Facebook Netconsd 缓冲区错误漏洞 — netconsd 9.8 - 2023-05-18
CVE-2023-28081 Facebook Hermes 资源管理错误漏洞 — Hermes 8.1 - 2023-05-18
CVE-2023-25933 Facebook Hermes 安全漏洞 — Hermes 9.8 - 2023-05-18
CVE-2023-24833 Facebook Hermes 资源管理错误漏洞 — Hermes 7.5 - 2023-05-18
CVE-2023-24832 Facebook Hermes 代码问题漏洞 — Hermes 7.5 - 2023-05-18
CVE-2023-23759 fizz 安全漏洞 — fizz 5.3 - 2023-05-18
CVE-2023-23557 Facebook Hermes 安全漏洞 — Hermes 10.0 - 2023-05-18
CVE-2023-23556 Facebook Hermes 缓冲区错误漏洞 — Hermes 9.8 - 2023-05-18
CVE-2022-36937 Facebook HHVM 安全漏洞 — HHVM 9.8 - 2023-05-10
CVE-2022-36938 Meta ReDex 缓冲区错误漏洞 — Redex CWE-125 9.8 - 2022-11-10
CVE-2022-40138 Facebook Hermes 安全漏洞 — Hermes CWE-681 9.8 - 2022-10-11

This page lists every published CVE security advisory associated with Facebook. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.