Comparison Overview
WORLDPAC

WORLDPAC
37137 Hickory St, Newark, CA, 94560, US
Last Update: 09/03/2026
WORLDPAC was formed in 1995 as a result of several acquisitions of the top tier import companies spanning over 30 years of service in the import aftermarket. WORLDPAC imports and distributes original equipment (OE) and quality aftermarket replacement automotive parts fo...

MAHLE
Pragstrasse 26-46, Stuttgart, D-70376, DE
Last Update: 20/09/2026
MAHLE is a leading international development partner and supplier to the automotive industry with customers in both passenger car and commercial vehicle sectors. Founded in 1920, the technology group is working on the climate-neutral mobility of tomorrow, with a focus o...
Compliance Ranges Comparison

WORLDPAC







MAHLE






Benchmark & Cyber Underwriting Signals
Incidents vs Motor Vehicle Manufacturing Industry Avg (This Year)
No incidents recorded for WORLDPAC in 2026.
Incidents vs Motor Vehicle Manufacturing Industry Avg (This Year)
No incidents recorded for MAHLE in 2026.
Incident History - WORLDPAC (X = Date, Y = Severity)
WORLDPAC cyber incidents detection timeline including parent company and subsidiaries.
Incident History - MAHLE (X = Date, Y = Severity)
MAHLE cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

WORLDPAC

MAHLE
FAQ
Latest Global CVEs
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki - WikiLambda extension: before 1.46.1.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS. This issue affects Mediawiki - Refreshed skin: before 1.46.1, 1.45.5, 1.43.10.
XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.
anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.
- https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3
- https://github.com/alexcorvi/anchorme.js
- https://github.com/alexcorvi/anchorme.js/blob/f3ae9850baa344f27b46bb149e9b891831d273b1/src/index.ts#L109
- https://www.npmjs.com/package/anchorme
- https://www.vulncheck.com/advisories/anchorme-through-3.0.8-regular-expression-denial-of-service