Comparison Overview
SOFACOMPANY

SOFACOMPANY
Selandia Park 1, Ringsted, 4100, DK
Last Update: 05/04/2026
At SOFACOMPANY we do things a bit differently, as especially seen in our unique approach to craftsmanship and innovation. We’ve taken full control of every link in our value chain, thereby managing everything ourselves from design, to sales, and to our own physical st...

Ashley Furniture Industries
One Ashley Way, Arcadia, WI, US, 54612
Last Update: 02/04/2026
Ashley Furniture Industries, LLC. (Ashley) is the largest furniture manufacturer in the United States and one of the largest in the world. Established in 1945, Ashley offers one of the industry’s broadest product assortments to retail partners in 155 countries. From des...
Compliance Ranges Comparison

SOFACOMPANY







Ashley Furniture Industries






Benchmark & Cyber Underwriting Signals
Incidents vs Furniture and Home Furnishings Manufacturing Industry Avg (This Year)
No incidents recorded for SOFACOMPANY in 2026.
Incidents vs Furniture and Home Furnishings Manufacturing Industry Avg (This Year)
No incidents recorded for Ashley Furniture Industries in 2026.
Incident History - SOFACOMPANY (X = Date, Y = Severity)
SOFACOMPANY cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Ashley Furniture Industries (X = Date, Y = Severity)
Ashley Furniture Industries cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

SOFACOMPANY

Ashley Furniture Industries
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.