Known Vulnerabilities for Ultimate by Avg
Listed below are 1 of the newest known vulnerabilities associated with "Ultimate" by "Avg".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66688 json | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2026-65516 json | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65510 json | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65505 json | Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65503 json | Contributor Cross Site Scripting (XSS) in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65499 json | Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-65439 json | Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-57830 json | The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-57829 json | The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS. | Not Provided | 2026-07-13 | 2026-07-13 |
| CVE-2026-27372 json | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | Not Provided | 2026-07-23 | 2026-07-23 |