Comparison Overview
NET-A-PORTER

NET-A-PORTER
1 The Village Offices, London, W12 7GF, GB
Last Update: 03/02/2026
NET-A-PORTER is the ultimate luxury fashion destination for women. Since 2000, it has offered customers a curated assortment of fashion, fine watches, jewelry and home décor, from the world’s most coveted brands. NET-A-PORTER creates unique experiences for its EIPs (Ext...

TFG (The Foschini Group)
340 Voortrekker Road, Cape Town, 7500, ZA
Last Update: 01/04/2026
TFG holds a diversified portfolio of speciality retail assets across various product categories and consumer segments. The Group has a portfolio of 35 leading retail brands, with over 4600 outlets in 23 countries on five continents, offering customers a variety of speci...
Compliance Ranges Comparison

NET-A-PORTER







TFG (The Foschini Group)






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for NET-A-PORTER in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for TFG (The Foschini Group) in 2026.
Incident History - NET-A-PORTER (X = Date, Y = Severity)
NET-A-PORTER cyber incidents detection timeline including parent company and subsidiaries.
Incident History - TFG (The Foschini Group) (X = Date, Y = Severity)
TFG (The Foschini Group) cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

NET-A-PORTER

TFG (The Foschini Group)
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.