Comparison Overview
WE Direct Lending, INC.

WE Direct Lending, INC.
3001 Douglas Blvd, Suite 220/142, Roseville, California, US, 95661
Last Update: 02/04/2026
WE Direct Lending is comprised of reputable business experts with illustrious experience in the financing industry. We promote the principle of financial inclusion, safe lending for the borrowers, and excellent opportunities for investors. We also aim to provide simple ...

SM Supermalls
Mall of Asia Complex, Pasay City, 1300, PH
Last Update: 14/09/2026
The SM Group of companies stands today as an institution, a store, a mall, a bank, a home, a resort, a hotel, and a place to see and experience with the family. One of the core business areas of the SM Group is the Shopping Center Management Corporation, generally ref...
Compliance Ranges Comparison

WE Direct Lending, INC.







SM Supermalls






Benchmark & Cyber Underwriting Signals
Incidents vs Real Estate Industry Avg (This Year)
No incidents recorded for WE Direct Lending, INC. in 2026.
Incidents vs Real Estate Industry Avg (This Year)
No incidents recorded for SM Supermalls in 2026.
Incident History - WE Direct Lending, INC. (X = Date, Y = Severity)
WE Direct Lending, INC. cyber incidents detection timeline including parent company and subsidiaries.
Incident History - SM Supermalls (X = Date, Y = Severity)
SM Supermalls cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

WE Direct Lending, INC.

SM Supermalls
FAQ
Latest Global CVEs
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a through 6.3.1.
OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal resources via an unvalidated jwks_uri. Attackers can trigger unauthenticated fetches through client-authentication and ID-token validation to probe internal hosts, metadata endpoints or local files, or exhaust request threads for denial of service.
OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. Authenticated accounts holding the iplanet-am-session-destroy-sessions attribute can supply a target session identifier or handle to forcibly log out users in any realm.