Comparison Overview
First American Data & Analytics

First American Data & Analytics
4 First American Way, Santa Ana, 92707, US
Last Update: 01/02/2026
First American Data & Analytics, a division of First American Financial Corporation, is a national provider of property-centric information, risk management and valuation solutions. First American maintains and curates the industry’s largest property and ownership datas...

CASA
CASA Building, Bedfordview, 2008, ZA
Last Update: 07/09/2026
CASA is an industry leading association that can provide you with the edge you need to be an effective business owner with a substantial property portfolio and gives you the power to confidently manage your business and structures to enable you, the business owner, to l...
Compliance Ranges Comparison

First American Data & Analytics







CASA






Benchmark & Cyber Underwriting Signals
Incidents vs Information Services Industry Avg (This Year)
No incidents recorded for First American Data & Analytics in 2026.
Incidents vs Information Services Industry Avg (This Year)
No incidents recorded for CASA in 2026.
Incident History - First American Data & Analytics (X = Date, Y = Severity)
First American Data & Analytics cyber incidents detection timeline including parent company and subsidiaries.
Incident History - CASA (X = Date, Y = Severity)
CASA cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

First American Data & Analytics

CASA
FAQ
Latest Global CVEs
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.