Comparison Overview
FabFitFun

FabFitFun
360 N La Cienega Blvd, Los Angeles, 90048, US
Last Update: 02/04/2026
Founded in 2010 by Co-CEOs Daniel and Michael Broukhim and Editor-in-Chief Katie Echevarria Rosen Kitchens, FabFitFun is a lifestyle membership and shopping experience whose mission is to deliver happiness and wellbeing to everyone, everywhere. Its flagship product, the...

Care.com
2801 N Central Expy, 11th Floor, Dallas, Texas, US, 75204
Last Update: 01/04/2026
Care.com is where families go to find care and where caregivers go to find meaningful work. Since 2007, over 45 million people have turned to Care.com—across child care, senior care, adult care, pet care and housekeeping. We’re here to make care simpler, smarter and mor...
Compliance Ranges Comparison

FabFitFun







Care.com






Benchmark & Cyber Underwriting Signals
Incidents vs Consumer Services Industry Avg (This Year)
No incidents recorded for FabFitFun in 2026.
Incidents vs Consumer Services Industry Avg (This Year)
No incidents recorded for Care.com in 2026.
Incident History - FabFitFun (X = Date, Y = Severity)
FabFitFun cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Care.com (X = Date, Y = Severity)
Care.com cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

FabFitFun

Care.com
FAQ
Latest Global CVEs
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.
A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected is the function unlink of the file app/Http/Controllers/Admin/helpdesk/SettingsController.php of the component Logo Handler. Such manipulation of the argument data1 leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the file app/Http/Controllers/Client/helpdesk/FormController.php of the component post-ticket-reply Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.