Comparison Overview
FuturePlan by Ascensus

FuturePlan by Ascensus
undefined, Dresher, Pennsylvania, 19025, US
Last Update: 19/12/2025
We stand as a Category of One partner in the TPA space. As a leading third party administrator for America’s leading recordkeepers and advisors, we are the only TPA offering a full spectrum of creative plan design, strategic consulting, IRS and DOL regulatory compliance...

SBI Card
Infinity Tower, DLF City Phase 2, Gurgaon, 122002, IN
Last Update: 10/09/2026
SBI Card was launched in 1998 with the State Bank of India, India's largest bank, as the majority stakeholder. In March 2020, SBI Card was listed on BSE and NSE. Today, SBI Card is India’s largest pure-play credit card issuer with over 20 million cards in force, as of D...
Compliance Ranges Comparison

FuturePlan by Ascensus







SBI Card






Benchmark & Cyber Underwriting Signals
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for FuturePlan by Ascensus in 2026.
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for SBI Card in 2026.
Incident History - FuturePlan by Ascensus (X = Date, Y = Severity)
FuturePlan by Ascensus cyber incidents detection timeline including parent company and subsidiaries.
Incident History - SBI Card (X = Date, Y = Severity)
SBI Card cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

FuturePlan by Ascensus

SBI Card
FAQ
Latest Global CVEs
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.