Comparison Overview
Galeries Lafayette

Galeries Lafayette
27, Rue de Châteaudun, Paris, Île-de-France, FR, 75009
Last Update: 04/04/2026
À la pointe des tendances, que le Groupe Galeries Lafayette a bien souvent initiées, il poursuit avec ses 15 000 collaborateurs cette success story avec ses marques emblématiques (Galeries Lafayette, BHV MARAIS, Louis Pion Royal Quartz, Didier Guérin et Citynove) et en ...

Walmart
702 SW 8th St, Bentonville, Arkansas, US, 72712
Last Update: 01/04/2026
Sixty years ago, Sam Walton started a single mom-and-pop shop and transformed it into the world’s biggest retailer. Since those founding days, one thing has remained consistent: our commitment to helping our customers save money so they can live better. Today, we’re rei...
Compliance Ranges Comparison

Galeries Lafayette







Walmart






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Galeries Lafayette in 2026.
Incidents vs Retail Industry Avg (This Year)
Walmart has 7.41% fewer incidents than the average of all companies with at least one recorded incident.
Incident History - Galeries Lafayette (X = Date, Y = Severity)
Galeries Lafayette cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Walmart (X = Date, Y = Severity)
Walmart cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Galeries Lafayette

Walmart
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.