CVEs we hold for Facebook
Records whose assigning authority named Facebook as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-68508Hydra: hydra.utils.instantiate with untrusted config can lead to code executionfacebookresearch hydra
CVE-2026-66707WordPress Facebook for WooCommerce plugin <= 3.7.5 - Cross Site Scripting (XSS) vulnerabilityFacebook for WooCommerce
CVE-2026-66705WordPress Facebook for WordPress plugin <= 5.2.1 - Cross Site Scripting (XSS) vulnerabilityFacebook for WordPress
CVE-2026-49059WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnerabilityFacebook for WooCommerce
CVE-2025-64296WordPress Facebook for WooCommerce plugin <= 3.5.7 - Broken Access Control to Notice Dismissal vulnerabilityFacebook for WooCommerce
CVE-2021-24218Facebook for WordPress 3.0.0-3.0.3 - CSRF to Stored XSS and Settings DeletionUnknown Facebook for WordPress
CVE-2021-24217Facebook for WordPress < 3.0.0 - PHP Object Injection with POP ChainUnknown Facebook for WordPress
CVE-2020-36838Facebook Chat Plugin <= 1.5 - Missing Capabilities CheckFacebook Chat Plugin – Live Chat Plugin for WordPress
151 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.