Exploited Vulnerabilities Daily
🌐 English

Home › Meta Platforms

CVE-2019-18426: Meta Platforms WhatsApp

EPSS67.8%No. 746 of 1739 in KEV
CVE year2019~3 yrs before listing
Same vendor in KEV3
Same product3
FieldValue
VendorMeta Platforms
ProductWhatsApp
NameWhatsApp Cross-Site Scripting Vulnerability
Added to KEV2022-05-23
US federal due date2022-06-13
Ransomware useUnknown
CWECWE-79

CISA description

A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2025-55177Meta Platforms WhatsApp2025-09-024.7%Unknown
CVE-2019-3568Meta Platforms WhatsApp2022-04-1930.0%Unknown

NVD — CVE-2019-18426

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Meta Platforms WhatsApp vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23.