ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Founded in 1991, Epic Games is a leading interactive entertainment company and provider of 3D engine technology. Epic operates Fortnite, one of the world’s largest games with over 350 million accounts and 2.5 billion friend connections. Epic also develops Unreal Engine, which powers the world’s leading games and is adopted across industries such as film and television, architecture, automotive, manufacturing, and simulation. Through Unreal Engine, Epic Games Store, and Epic Online Services, Epic provides an end-to-end digital ecosystem for developers and creators to build, distribute, and operate games and other content. Epic has over 40 offices worldwide with headquarters in Cary, North Carolina.

Epic Games A.I CyberSecurity Scoring

Epic Games

Company Details

Linkedin ID:

epic-games

Employees number:

10,599

Number of followers:

830,671

NAICS:

51126

Industry Type:

Computer Games

Homepage:

epicgames.com

IP Addresses:

0

Company ID:

EPI_9930560

Scan Status:

In-progress

AI scoreEpic Games Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/epic-games.jpeg
Epic Games Computer Games
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreEpic Games Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/epic-games.jpeg
Epic Games Computer Games
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Epic Games Company CyberSecurity News & History

Past Incidents
4
Attack Types
3
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Epic GamesCyber Attack1006/2025
Rankiteo Explanation :
Attack threatening the organization’s existence

Description: Stormous, a hacker collective, has been leveraging cyberattacks as political acts, targeting high-profile entities such as ministries, regions, and major economic players like Epic Games. Their strategy involves stealing data and then blackmailing the victims with the threat of publication. This tactic not only seeks financial gain but also aims to destabilize targeted organizations, making each attack a significant threat to both financial and reputational stability.

Epic GamesData Leak60412/2022
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: The fined Epic Games, the video game company behind Fortnite, was fined $520 million by the US Federal Trade Commission (FTC) for non-compliance with the Children's Online Privacy Protection Act (COPPA). Epic Games have to pay $275 million for violating COPPA and another $245 million in refunds for tricking users into making unwanted charges and, changing the default privacy settings. The company intentionally stored personal information, such as names and emails, of its Fortnite subscribers, including minors. With this data, the firm monitors their activity within the game. In the case of minors, Epic Games did not have parental consent.

Epic GamesData Leak85308/2016
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: The Epic Games forums were compromised, exposing 808,000 Unreal Engine and Unreal Tournament forum accounts' salted passwords. Email addresses, birth dates, and private messages are among the information taken from Epic Games. Security experts have expressed dissatisfaction with the degree of security put in place to safeguard customers' data. In response, the firm has stated that it would not be forcing account resets because passwords on the Unreal forums were not compromised. Additionally, the Facebook access tokens that were stored in the database for individuals who logged in using their social account were accessible to the attackers.

Unreal EngineBreach100508/2016
Rankiteo Explanation :
Attack threatening the organization's existence

Description: The hackers infiltrated the systems of Unreal Engine by SQL injection vulnerability which allowed the hacker to get access to the full database. A hacker has stolen thousands of forum accounts associated with Unreal Engine and its maker, Epic Games. The hacker acquired usernames, scrambled passwords, email addresses, IP addresses, birthdates, join dates, their full history of posts and comments including private messages, and other user activity data from both sets of forums. They immediately investigated the incident and took preventive steps.

Epic Games
Cyber Attack
Severity: 100
Impact:
Seen: 6/2025
Blog:
Rankiteo Explanation
Attack threatening the organization’s existence

Description: Stormous, a hacker collective, has been leveraging cyberattacks as political acts, targeting high-profile entities such as ministries, regions, and major economic players like Epic Games. Their strategy involves stealing data and then blackmailing the victims with the threat of publication. This tactic not only seeks financial gain but also aims to destabilize targeted organizations, making each attack a significant threat to both financial and reputational stability.

Epic Games
Data Leak
Severity: 60
Impact: 4
Seen: 12/2022
Blog:
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: The fined Epic Games, the video game company behind Fortnite, was fined $520 million by the US Federal Trade Commission (FTC) for non-compliance with the Children's Online Privacy Protection Act (COPPA). Epic Games have to pay $275 million for violating COPPA and another $245 million in refunds for tricking users into making unwanted charges and, changing the default privacy settings. The company intentionally stored personal information, such as names and emails, of its Fortnite subscribers, including minors. With this data, the firm monitors their activity within the game. In the case of minors, Epic Games did not have parental consent.

Epic Games
Data Leak
Severity: 85
Impact: 3
Seen: 08/2016
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: The Epic Games forums were compromised, exposing 808,000 Unreal Engine and Unreal Tournament forum accounts' salted passwords. Email addresses, birth dates, and private messages are among the information taken from Epic Games. Security experts have expressed dissatisfaction with the degree of security put in place to safeguard customers' data. In response, the firm has stated that it would not be forcing account resets because passwords on the Unreal forums were not compromised. Additionally, the Facebook access tokens that were stored in the database for individuals who logged in using their social account were accessible to the attackers.

Unreal Engine
Breach
Severity: 100
Impact: 5
Seen: 08/2016
Blog:
Rankiteo Explanation
Attack threatening the organization's existence

Description: The hackers infiltrated the systems of Unreal Engine by SQL injection vulnerability which allowed the hacker to get access to the full database. A hacker has stolen thousands of forum accounts associated with Unreal Engine and its maker, Epic Games. The hacker acquired usernames, scrambled passwords, email addresses, IP addresses, birthdates, join dates, their full history of posts and comments including private messages, and other user activity data from both sets of forums. They immediately investigated the incident and took preventive steps.

Ailogo

Epic Games Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Epic Games

Incidents vs Computer Games Industry Average (This Year)

Epic Games has 12.36% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

Epic Games has 28.21% more incidents than the average of all companies with at least one recorded incident.

Incident Types Epic Games vs Computer Games Industry Avg (This Year)

Epic Games reported 1 incidents this year: 1 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.

Incident History — Epic Games (X = Date, Y = Severity)

Epic Games cyber incidents detection timeline including parent company and subsidiaries

Epic Games Company Subsidiaries

SubsidiaryImage

Founded in 1991, Epic Games is a leading interactive entertainment company and provider of 3D engine technology. Epic operates Fortnite, one of the world’s largest games with over 350 million accounts and 2.5 billion friend connections. Epic also develops Unreal Engine, which powers the world’s leading games and is adopted across industries such as film and television, architecture, automotive, manufacturing, and simulation. Through Unreal Engine, Epic Games Store, and Epic Online Services, Epic provides an end-to-end digital ecosystem for developers and creators to build, distribute, and operate games and other content. Epic has over 40 offices worldwide with headquarters in Cary, North Carolina.

Loading...
similarCompanies

Epic Games Similar Companies

Keywords Studios

🎮🎬 We help make video games, films, and fan favourites you’ve probably played, watched, or heard. We work behind the scenes with game developers, publishers, and entertainment companies to bring their ideas to life and keep them running smoothly. From game development and art production to audio se

Ubisoft is a global leader in gaming with teams across the world crafting original and memorable gaming experiences featuring brands such as Assassin’s Creed®, Brawlhalla®, For Honor®, Far Cry®, Tom Clancy’s Ghost Recon®, Just Dance®, Rabbids®, Tom Clancy’s Rainbow Six®, The Crew® and Tom Clancy’s T

newsone

Epic Games CyberSecurity News

December 11, 2025 07:45 PM
Epic Games' Fortnite is back in US Google Play Store, as court partially reverses restrictions it won on iOS

Epic Games' popular battle royale, Fortnite, has returned to the U.S. Google Play Store following a court order. The game maker had recently...

November 05, 2025 08:00 AM
Google latest: DOJ hurdle cleared, Epic Games settlement reached

Yahoo Finance's John Hyland tracks Wednesday's top moving stocks and biggest market stories in this Market Minute.

November 02, 2025 07:00 AM
Epic Games restores services after major outage hits Fortnite, Rocket League, and Fall Guys

Gaming News: Epic Games faced a widespread outage, impacting access to popular titles like Fortnite, Rocket League, and Fall Guys.

October 07, 2025 07:00 AM
Major gaming platforms hit by disruptions: unprecedented DDoS suspected

Multiplayer gamers on different platforms have experienced service outages and disruptions simultaneously. The cybersecurity community...

October 01, 2025 07:00 AM
Epic Games Store iOS installs soar as DMA pressures Apple in EU

It looks like the DMA is finally making things a bit easier for Apple users trying to install the Epic Games Store on iOS in the EU.

September 23, 2025 07:00 AM
Atos to provide cyber security services to EU

Atos will be the lead contractor in a consortium with Leonardo to provide cyber security services to the European Union, the Paris listed...

August 13, 2025 07:00 AM
Epic Games has another win over Apple and Google, this time in Australia

Australia's Federal Court has given Epic Games another win in its global fight against the way Apple and Google run their app stores.

July 08, 2025 07:00 AM
Epic Games and Samsung settle app store competition case

Epic Games has settled the case it brought against Samsung over the Korean giant's treatment of third-party app stores on its Galaxy handsets.

June 18, 2025 07:00 AM
Game over? How cyberfrauds are infiltrating Gen Z’s favorite games - ET Edge Insights

Cybersecurity firm Kaspersky detected over 19 million attempts globally to spread malware disguised as popular Gen Z games like GTA, Minecraft, and Call of...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Epic Games CyberSecurity History Information

Official Website of Epic Games

The official website of Epic Games is http://www.epicgames.com/.

Epic Games’s AI-Generated Cybersecurity Score

According to Rankiteo, Epic Games’s AI-generated cybersecurity score is 710, reflecting their Moderate security posture.

How many security badges does Epic Games’ have ?

According to Rankiteo, Epic Games currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Epic Games have SOC 2 Type 1 certification ?

According to Rankiteo, Epic Games is not certified under SOC 2 Type 1.

Does Epic Games have SOC 2 Type 2 certification ?

According to Rankiteo, Epic Games does not hold a SOC 2 Type 2 certification.

Does Epic Games comply with GDPR ?

According to Rankiteo, Epic Games is not listed as GDPR compliant.

Does Epic Games have PCI DSS certification ?

According to Rankiteo, Epic Games does not currently maintain PCI DSS compliance.

Does Epic Games comply with HIPAA ?

According to Rankiteo, Epic Games is not compliant with HIPAA regulations.

Does Epic Games have ISO 27001 certification ?

According to Rankiteo,Epic Games is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Epic Games

Epic Games operates primarily in the Computer Games industry.

Number of Employees at Epic Games

Epic Games employs approximately 10,599 people worldwide.

Subsidiaries Owned by Epic Games

Epic Games presently has no subsidiaries across any sectors.

Epic Games’s LinkedIn Followers

Epic Games’s official LinkedIn profile has approximately 830,671 followers.

NAICS Classification of Epic Games

Epic Games is classified under the NAICS code 51126, which corresponds to Software Publishers.

Epic Games’s Presence on Crunchbase

No, Epic Games does not have a profile on Crunchbase.

Epic Games’s Presence on LinkedIn

Yes, Epic Games maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/epic-games.

Cybersecurity Incidents Involving Epic Games

As of December 21, 2025, Rankiteo reports that Epic Games has experienced 4 cybersecurity incidents.

Number of Peer and Competitor Companies

Epic Games has an estimated 1,994 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Epic Games ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack, Data Leak and Breach.

What was the total financial impact of these incidents on Epic Games ?

Total Financial Loss: The total financial loss from these incidents is estimated to be $520 million.

How does Epic Games detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an remediation measures with no forced account resets..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Unreal Engine Forum Data Breach

Description: Hackers infiltrated the systems of Unreal Engine by exploiting an SQL injection vulnerability, gaining access to the full database and stealing thousands of forum accounts associated with Unreal Engine and its maker, Epic Games.

Type: Data Breach

Attack Vector: SQL Injection

Vulnerability Exploited: SQL Injection Vulnerability

Threat Actor: Hacker

Motivation: Data Theft

Incident : Data Privacy Violation

Title: Epic Games Fined for COPPA Violations and Unwanted Charges

Description: Epic Games, the video game company behind Fortnite, was fined $520 million by the US Federal Trade Commission (FTC) for non-compliance with the Children's Online Privacy Protection Act (COPPA). The company has to pay $275 million for violating COPPA and another $245 million in refunds for tricking users into making unwanted charges and changing the default privacy settings. The company intentionally stored personal information, such as names and emails, of its Fortnite subscribers, including minors. With this data, the firm monitors their activity within the game. In the case of minors, Epic Games did not have parental consent.

Type: Data Privacy Violation

Threat Actor: Epic Games

Motivation: Financial Gain

Incident : Data Breach

Title: Epic Games Forum Breach

Description: The Epic Games forums were compromised, exposing 808,000 Unreal Engine and Unreal Tournament forum accounts' salted passwords. Email addresses, birth dates, and private messages are among the information taken from Epic Games. Security experts have expressed dissatisfaction with the degree of security put in place to safeguard customers' data. In response, the firm has stated that it would not be forcing account resets because passwords on the Unreal forums were not compromised. Additionally, the Facebook access tokens that were stored in the database for individuals who logged in using their social account were accessible to the attackers.

Type: Data Breach

Incident : Double Extortion

Title: Stormous Cyberattacks

Description: L'ADN de Stormous ne se résume pas à la seule recherche de profit. Depuis le début du conflit ukrainien, le collectif affiche ouvertement son soutien à Moscou, en transformant chaque cyberattaque en acte politique. Cette stratégie de double extorsion, qui se matérialise par le vol de données d'abord et chantage à la publication ensuite, vise autant l'enrichissement que la déstabilisation. Les cibles choisies ne sont en plus jamais anodines. On y retrouve des ministères, des régions, mais aussi géants économiques comme Coca-Cola, Volkswagen ou Epic Games.

Type: Double Extortion

Threat Actor: Stormous

Motivation: Financial GainPolitical Motivations

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Data Leak.

How does the company identify the attack vectors used in incidents ?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through SQL Injection Vulnerability.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach UNR211631522

Data Compromised: Usernames, Scrambled passwords, Email addresses, Ip addresses, Birthdates, Join dates, Post history, Comments, Private messages, Other user activity data

Systems Affected: Forum Systems

Incident : Data Privacy Violation EPI32022123

Financial Loss: $275 million for COPPA violation$245 million in refunds

Data Compromised: Names, Emails

Legal Liabilities: COPPA Violation

Incident : Data Breach EPI2054291023

Data Compromised: Email addresses, Birth dates, Private messages, Facebook access tokens

Systems Affected: Unreal Engine and Unreal Tournament forums

Brand Reputation Impact: negative

Incident : Double Extortion EPI601061625

What is the average financial loss per incident ?

Average Financial Loss: The average financial loss per incident is $130.00 million.

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Usernames, Scrambled Passwords, Email Addresses, Ip Addresses, Birthdates, Join Dates, Post History, Comments, Private Messages, Other User Activity Data, , Personal Information, , Email Addresses, Birth Dates, Private Messages, Facebook Access Tokens and .

Which entities were affected by each incident ?

Incident : Data Breach UNR211631522

Entity Name: Epic Games

Entity Type: Company

Industry: Gaming

Customers Affected: Thousands

Incident : Data Privacy Violation EPI32022123

Entity Name: Epic Games

Entity Type: Company

Industry: Video Game

Incident : Data Breach EPI2054291023

Entity Name: Epic Games

Entity Type: Company

Industry: Gaming

Customers Affected: 808,000

Incident : Double Extortion EPI601061625

Entity Name: Coca-Cola

Entity Type: Corporation

Industry: Beverage

Incident : Double Extortion EPI601061625

Entity Name: Volkswagen

Entity Type: Corporation

Industry: Automotive

Incident : Double Extortion EPI601061625

Entity Name: Epic Games

Entity Type: Corporation

Industry: Gaming

Incident : Double Extortion EPI601061625

Entity Name: Various Ministries and Regions

Entity Type: Government

Industry: Public Sector

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach EPI2054291023

Remediation Measures: No forced account resets

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach UNR211631522

Type of Data Compromised: Usernames, Scrambled passwords, Email addresses, Ip addresses, Birthdates, Join dates, Post history, Comments, Private messages, Other user activity data

Number of Records Exposed: Thousands

Sensitivity of Data: High

Data Encryption: Scrambled Passwords

Personally Identifiable Information: usernamesemail addressesIP addressesbirthdatesjoin dates

Incident : Data Privacy Violation EPI32022123

Type of Data Compromised: Personal information

Sensitivity of Data: High

Incident : Data Breach EPI2054291023

Type of Data Compromised: Email addresses, Birth dates, Private messages, Facebook access tokens

Number of Records Exposed: 808,000

Data Encryption: ['salted passwords']

Personally Identifiable Information: email addressesbirth dates

Incident : Double Extortion EPI601061625

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: No forced account resets.

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : Double Extortion EPI601061625

Ransom Demanded: True

Data Exfiltration: True

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Data Privacy Violation EPI32022123

Regulations Violated: COPPA

Fines Imposed: $520 million

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Data Breach UNR211631522

Investigation Status: Investigated and Preventive Steps Taken

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Data Breach UNR211631522

Entry Point: SQL Injection Vulnerability

Incident : Double Extortion EPI601061625

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach UNR211631522

Root Causes: SQL Injection Vulnerability

Additional Questions

General Information

What was the amount of the last ransom demanded ?

Last Ransom Demanded: The amount of the last ransom demanded was True.

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident were an Hacker, Epic Games and Stormous.

Impact of the Incidents

What was the highest financial loss from an incident ?

Highest Financial Loss: The highest financial loss from an incident was ['$275 million for COPPA violation', '$245 million in refunds'].

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were usernames, scrambled passwords, email addresses, IP addresses, birthdates, join dates, post history, comments, private messages, other user activity data, , Names, Emails, , email addresses, birth dates, private messages, Facebook access tokens, and .

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was Unreal Engine and Unreal Tournament forums.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were private messages, post history, email addresses, usernames, Names, Facebook access tokens, other user activity data, comments, scrambled passwords, birthdates, join dates, birth dates, Emails and IP addresses.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 808.0K.

Ransomware Information

What was the highest ransom demanded in a ransomware incident ?

Highest Ransom Demanded: The highest ransom demanded in a ransomware incident was True.

Regulatory Compliance

What was the highest fine imposed for a regulatory violation ?

Highest Fine Imposed: The highest fine imposed for a regulatory violation was $520 million.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Investigated and Preventive Steps Taken.

Initial Access Broker

What was the most recent entry point used by an initial access broker ?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an SQL Injection Vulnerability.

cve

Latest Global CVEs (Not Company-Specific)

Description

Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper privilege handling and a time-of-check time-of-use race condition combined with symbolic link and mount point manipulation, a local authenticated attacker can coerce the service into deleting arbitrary directories with SYSTEM privileges. This can be exploited to delete protected system folders such as C:\\Config.msi and subsequently achieve execution as NT AUTHORITY\\SYSTEM via MSI rollback techniques.

Risk Information
cvss4
Base: 8.5
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due to a missing capability check on the 'cs_update_application_status_callback' function in all versions up to, and including, 7.7. This makes it possible for authenticated attackers, with Candidate-level access and above, to inject cross-site scripting into the 'status' parameter of applied jobs for any user.

Risk Information
cvss3
Base: 7.6
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Description

The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.7 via the 'cs_update_application_status_callback' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Candidate-level access and above, to send a site-generated email with injected HTML to any user.

Risk Information
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Description

The FiboSearch – Ajax Search for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `thegem_te_search` shortcode in all versions up to, and including, 1.32.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires TheGem theme (premium) to be installed with Header Builder mode enabled, and the FiboSearch "Replace search bars" option enabled for TheGem integration.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Description

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.0 via the ajax_get_members function. This is due to the use of a predictable low-entropy token (5 hex characters derived from md5 of post ID) to identify member directories and insufficient authorization checks on the unauthenticated AJAX endpoint. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, display names, user roles (including administrator accounts), profile URLs, and user IDs by enumerating predictable directory_id values or brute-forcing the small 16^5 token space.

Risk Information
cvss3
Base: 5.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=epic-games' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge