Archives
- 16 Nov Internal Paths/Files Leakage via Malformed Access Token on graph.meta.ai
- 15 Nov IDOR - Unauthorized Meta Verified Waitlist Modification
- 01 Nov Toggle Messaging Notification for Any Meta Horizon Account
- 02 Oct Exposes Private Facebook/Workplace Videos for any user
- 15 Sep Delete Any Ads Reporting Preview Shared with Others
- 04 Sep Business Suite (Paid Partnership) - Add Creator to Any Instagram Account
- 01 Sep Page Insight Can Add Questions to Pages
- 11 Aug Join Workplace Without Approval of Workplace Admin
- 03 Aug Mark Marketplace Item as Paid as a Buyer
- 18 Jun Block Appointments Requests for Any Facebook Page
- 15 Jun Disclosing Private Group Members via Facebook Rooms
- 21 May Takeover any wit.ai account
- 02 May View Draft, Archived and Inactive Effects for Any Facebook or Instagram User
- 01 May View Reports Ad Account for Any Business (Export via Report ID)
- 27 Apr Business Partner Can Escalate Role on Block Lists
- 12 Apr Delete Groups AR Studio Effect
- 09 Apr Bypass Pixel Role (Partner Business)
- 18 Mar Disclose Page Admins via Facebook Appointments
- 06 Mar View Pending Email of Any Oculus User via GraphQL