Yuuuuup. People think FB is free of these problems because they have written some highly performant code and have a shit ton of money.
Nope, money doesnt cure laziness and definitely doesnt cure "it works so why fix it".
Pretty much, it's expected when you're small for security to take a backseat to convenience. However, when you reach the point of billions of users, every line of code should be reviewed and there's no excuse for something this simple to slip by.