Comparison Overview
Caption by Hyatt

Caption by Hyatt
N/A
Last Update: 25/01/2026
Caption by Hyatt is the upscale, select-service lifestyle brand that attracts conscientious locals and guests throughout the day to use its social spaces to connect and interact with one another and the places around them – redefining what hospitality looks like in the ...

Wyndham Hotels & Resorts
22 Sylvan Way, Parsippany, 07054, US
Last Update: 03/10/2026
We are Wyndham Hotels & Resorts. We are the world’s largest hotel franchising company by the number of franchised properties, with approximately 8,300 hotels across approximately 100 countries on six continents. We operate a portfolio of 25 hotel brands: Whether choosi...
Compliance Ranges Comparison

Caption by Hyatt







Wyndham Hotels & Resorts






Benchmark & Cyber Underwriting Signals
Incidents vs Hospitality Industry Avg (This Year)
No incidents recorded for Caption by Hyatt in 2026.
Incidents vs Hospitality Industry Avg (This Year)
No incidents recorded for Wyndham Hotels & Resorts in 2026.
Incident History - Caption by Hyatt (X = Date, Y = Severity)
Caption by Hyatt cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Wyndham Hotels & Resorts (X = Date, Y = Severity)
Wyndham Hotels & Resorts cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Caption by Hyatt

Wyndham Hotels & Resorts
FAQ
Latest Global CVEs
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.