The Facebook Pixel Project's vulnerability footprint centers on its tracking and analytics pixel product, a web-embedded component deployed across publisher and advertiser sites for conversion measurement and audience segmentation. The durable signal in disclosed vulnerabilities reflects the pixel's role in cross-origin JavaScript contexts, with recurring exposure to cross-site scripting and input-neutralization weaknesses inherent to client-side script injection in third-party pages; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Facebook Pixel Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14557MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Facebook Pixel facebook_pixel allows Stored XSS.This issue affec | Jan 14, 2026 | 4.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Facebook Pixel Project.
Media articles that mention a CVE ID that affects a product developed by Facebook Pixel Project — matched by CVE ID, not by vendor name.