Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

Wyndham Hotels & ResortsWyndham Hotels & Resorts
VS
IHG Hotels & ResortsIHG Hotels & Resorts
Wyndham Hotels & Resorts

Wyndham Hotels & Resorts

22 Sylvan Way, Parsippany, 07054, US

Last Update: 03/10/2026

View Profile
791/1000Fair

We are Wyndham Hotels & Resorts. We are the world’s largest hotel franchising company by the number of franchised properties, with approximately 8,300 hotels across approximately 100 countries on six continents. We operate a portfolio of 25 hotel brands: Whether choosi...

NAICS:7211
NAICS Definition:Traveler Accommodation
Employees:10,254
Subsidiaries:4
12-month incidents
0
Known data breaches
0
Attack type number
0
IHG Hotels & Resorts

IHG Hotels & Resorts

Windsor Dials 1, Arthur Road, Windsor, Berkshire, GB, SL4 1RS

Last Update: 25/09/2026

View Profile
Between 750 and 799
http://www.ihgplc.com
777/1000Fair

IHG Hotels & Resorts [LON:IHG, NYSE:IHG (ADRs)] is a global hospitality company, with a purpose to provide True Hospitality for Good. With a family of 21 hotel brands and IHG One Rewards, one of the world's largest hotel loyalty programmes with over 160 million members...

NAICS:7211
NAICS Definition:Traveler Accommodation
Employees:19,448
Subsidiaries:5
12-month incidents
0
Known data breaches
2
Attack type number
2

Compliance Ranges Comparison

Based On Specific Ai Models Category
Wyndham Hotels & Resorts

Wyndham Hotels & Resorts

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
IHG Hotels & Resorts

IHG Hotels & Resorts

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Hospitality Industry Avg (This Year)

No incidents recorded for Wyndham Hotels & Resorts in 2026.

Incidents

Incidents vs Hospitality Industry Avg (This Year)

No incidents recorded for IHG Hotels & Resorts in 2026.

Incidents

Incident History - Wyndham Hotels & Resorts (X = Date, Y = Severity)

Wyndham Hotels & Resorts cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - IHG Hotels & Resorts (X = Date, Y = Severity)

IHG Hotels & Resorts cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
Wyndham Hotels & Resorts

Wyndham Hotels & Resorts

Incidents
No explicit notable incidents reported.
IHG Hotels & Resorts

IHG Hotels & Resorts

Incidents
🔒 Incident : Cyber Attack
IHG223521922
🔒 Incident : Breach
IHGHCLGAPWYNMCDVODKYNMIC1786975327
🔒 Incident : Cyber Attack
IHG1056072825

FAQ

Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has the best AI Cybersecurity Score ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has experienced more cyber incidents in the past ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has experienced more cyber incidents this year ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has experienced at least one ransomware attack ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has experienced at least one data breach ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has experienced at least one targeted cyberattack ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has experienced at least one vulnerability ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one holds the most compliance certifications ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one holds the fewest compliance certifications ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has the most subsidiaries ?
Between Wyndham Hotels & Resorts company and IHG Hotels & Resorts company, which one has the largest number of employees ?
Between Wyndham Hotels & Resorts and IHG Hotels & Resorts, which company holds both SOC 2 Type 1 certifications ?
Between Wyndham Hotels & Resorts and IHG Hotels & Resorts, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - Wyndham Hotels & Resorts or IHG Hotels & Resorts ?
Which company is PCI DSS compliant - Wyndham Hotels & Resorts or IHG Hotels & Resorts ?
Between Wyndham Hotels & Resorts and IHG Hotels & Resorts, which company complies with HIPAA regulations for healthcare data ?
Between Wyndham Hotels & Resorts and IHG Hotels & Resorts, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-108680
SUMMARY

JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to send template notifications by calling POST /sys/api/sendTemplateAnnouncement. Low-privileged attackers can supply forged sender, recipients, title, and template parameters to deliver messages appearing to come from admin or system accounts.

PUBLISHED
Date2026-10-10
UPDATED
Date2026-10-10
RISK INFORMATION (Score: 4.3)
CVSS3
Base Score: 4.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS4
Base Score: 5.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
1.4
EXPLOITABILITY
2.8
CVE-2026-108679
SUMMARY

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attackers can POST crafted bodies to /sys/api/sendBusAnnouncement with forged sender, recipients, title and content to deliver spoofed admin or system messages for phishing.

PUBLISHED
Date2026-10-10
UPDATED
Date2026-10-10
RISK INFORMATION (Score: 4.3)
CVSS3
Base Score: 4.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS4
Base Score: 5.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
1.4
EXPLOITABILITY
2.8
CVE-2026-108678
SUMMARY

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRoles handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send GET requests to /sys/api/queryUserRoles with an arbitrary username to enumerate role assignments and identify administrator accounts.

PUBLISHED
Date2026-10-10
UPDATED
Date2026-10-10
RISK INFORMATION (Score: 4.3)
CVSS3
Base Score: 4.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS4
Base Score: 5.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
1.4
EXPLOITABILITY
2.8
CVE-2026-108677
SUMMARY

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in GET /sys/api/getUserByName that allows low-privileged authenticated users to retrieve any user's stored password value. Attackers can decrypt the AES-CBC protected response using the hard-coded key exposed by /sys/getEncryptedString to obtain administrators' password ciphertexts for offline guessing.

PUBLISHED
Date2026-10-10
UPDATED
Date2026-10-10
RISK INFORMATION (Score: 6.5)
CVSS3
Base Score: 6.5
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS4
Base Score: 7.1
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.6
EXPLOITABILITY
2.8
CVE-2026-108676
SUMMARY

JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysAnnouncementController downLoadFiles handler that allows low-privileged authenticated users to download announcement attachments. Attackers can supply a known announcement id to retrieve a ZIP of attachments from unreleased announcements or those addressed only to other users.

PUBLISHED
Date2026-10-10
UPDATED
Date2026-10-10
RISK INFORMATION (Score: 4.3)
CVSS3
Base Score: 4.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS4
Base Score: 5.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
1.4
EXPLOITABILITY
2.8