On this page
CWE-20: Improper Input Validation
Weakness Summary
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
- Canonical source: MITRE CWE-20 (opens in a new tab)
- Published Atomicorp CVE observations: 72
- Distinct affected products in those observations: 62
- Active Atomicorp rules associated with this weakness: 76
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2009-0545 | ZeroShell <= 1.0beta11 Remote Code Execution | zeroshell | Attack Blocked by Atomicorp | 312657 , 340007 , 340029 , 344360 , 344370 , 347009 , 390709 |
| CVE-2021-44228 | Apache Log4j2 Remote Code Injection | log4j | Attack Blocked by Atomicorp | 345115 , 345117 , 345118 , 393655 |
| CVE-2024-22476 | Intel Neural Compressor <2.5.0 - SQL Injection | Intel(R) Neural Compressor software | Attack Blocked by Atomicorp | 341245 |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | dbgate | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 360151 , 380026 |
| CVE-2010-4239 | Tiki Wiki CMS Groupware 5.2 - Local File Inclusion | tikiwiki cms/groupware | Attack Blocked by Atomicorp | 340007 , 390109 |
| CVE-2014-3206 | Seagate BlackArmor NAS - Command Injection | blackarmor nas 220 firmware | Attack Blocked by Atomicorp | 311235 , 340014 , 340193 , 344364 , 344366 |
| CVE-2015-4664 | Xceedium Xsuite - Multiple Vulnerabilities | privileged access manager | Attack Blocked by Atomicorp | 320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648 |
| CVE-2016-5674 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | readynas surveillance | Attack Blocked by Atomicorp | 344363 , 392301 |
| CVE-2016-5675 | NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities | readynas surveillance | Attack Blocked by Atomicorp | 392301 |
| CVE-2016-6603 | WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities | webnms framework | Attack Blocked by Atomicorp | 390727 , 392301 , 392648 |
| CVE-2017-12611 | Apache Struts2 S2-053 - Remote Code Execution | struts | Attack Blocked by Atomicorp | 337207 , 337209 , 337211 , 337218 , 340014 , 340029 , 340193 , 344360 , 344362 , 344363 , 344370 , 347009 |
| CVE-2017-16935 | Ametys CMS 4.0.2 - Password Reset | ametys | Attack Blocked by Atomicorp | 345493 , 390724 |
| CVE-2017-18349 | Fastjson Insecure Deserialization - Remote Code Execution | fastjson | Attack Blocked by Atomicorp | 344380 , 344385 , 398008 |
| CVE-2017-18580 | WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution | shortcodes ultimate | Detected by Atomicorp | 377360 |
| CVE-2017-9791 | Apache Struts2 S2-053 - Remote Code Execution | struts | Attack Blocked by Atomicorp | 337207 |
| CVE-2017-9811 | Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities | anti-virus for linux server | Attack Blocked by Atomicorp | 390704 , 390724 |
| CVE-2018-11686 | FlexPaper/FlowPaper 2.3.6 - Remote Code Execution | flowpaper | Attack Blocked by Atomicorp | 340029 , 344361 , 344364 |
| CVE-2018-20985 | WordPress Payeezy Pay <=2.97 - Local File Inclusion | wp payeezy pay | Attack Blocked by Atomicorp | 392301 |
| CVE-2018-7600 | Drupal - Remote Code Execution | drupal | Attack Blocked by Atomicorp | 330791 , 340152 |
| CVE-2020-13942 | Apache Unomi <1.5.2 - Remote Code Execution | unomi | Attack Blocked by Atomicorp | 340095 |
| CVE-2021-21978 | VMware View Planner <4.6 SP1- Remote Code Execution | view planner | Attack Blocked by Atomicorp | 330791 , 340007 , 340152 |
| CVE-2022-24086 | Adobe Commerce (Magento) - Remote Code Execution | commerce | Attack Blocked by Atomicorp | 344360 , 344370 |
| CVE-2023-3710 | Honeywell PM43 Printers - Command Injection | pm43 firmware | Attack Blocked by Atomicorp | 344361 , 344363 |
| CVE-2025-54123 | Hoverfly <= 1.11.3 - Remote Code Execution | hoverfly | Attack Blocked by Atomicorp | 344360 |
| CVE-2026-19912 | Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution Vulnerability | Kaltura HTML5 Video Player, html5 library | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2026-35048 | Piwigo RCE via PHP Code Injection into Config File in Installer | Piwigo | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-49827 | WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434) | WebErpMesv2 | Attack Blocked by Atomicorp | 351000 |
| CVE-2026-53513 | Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration | better-auth/sso | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-54694 | NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover | skills-service | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-44343 | WGDashboard < 4.3.2 - Unauthenticated File Read | wgdashboard | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2024-5276 | Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection | filecatalyst workflow | Attack Blocked by Atomicorp | 341245 |
| CVE-2026-41042 | Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution | gravitino | Attack Blocked by Atomicorp | 344370 |
| CVE-2026-57499 | Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE) | core | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2016-10960 | WordPress wSecure Lite < 2.4 - Remote Code Execution | wsecure | Attack Blocked by Atomicorp | 392301 |
| CVE-2024-7340 | W&B Weave Server - Remote Arbitrary File Leak | - | Attack Blocked by Atomicorp | 347009 |
| CVE-2026-24893 | openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro Expansion | openitcockpit | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-34197 | Apache ActiveMQ - Remote Code Execution | activemq | Attack Blocked by Atomicorp | 330925 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-35031 | Jellyfin: Potential RCE via subtitle upload path traversal + .strm chain | jellyfin | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-40466 | Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypass | activemq | Attack Blocked by Atomicorp | 330925 , 340162 , 340163 |
| CVE-2026-45505 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper Bypass | activemq | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2025-34115 | OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php | OP5 Monitor | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-28797 | RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compone | ragflow | Attack Blocked by Atomicorp | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-50553 | Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p) | note-mark | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-73658 | Trigger.dev: Cross-tenant object store read and write via URL path traversal | trigger.dev | Attack Blocked by Atomicorp | 347009 |
| CVE-2017-15715 | Apache httpd <=2.4.29 - Arbitrary File Upload | http server | Attack Blocked by Atomicorp | 344365 |
| CVE-2023-26067 | Lexmark Printers - Command Injection | cxtpc firmware | Attack Blocked by Atomicorp | 392301 |
| CVE-2024-30188 | Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And Write | dolphinscheduler | Attack Blocked by Atomicorp | 340162 , 340165 , 344360 , 347009 , 390726 , 392647 |
| CVE-2026-42588 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector | activemq | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-69192 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trus | ip-address | Attack Blocked by Atomicorp | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2016-10956 | WordPress Mail Masta 1.0 - Local File Inclusion | mail-masta | Attack Blocked by Atomicorp | 344360 , 347009 , 390709 |
| CVE-2016-1328 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | Attack Blocked by Atomicorp | 333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648 |
| CVE-2016-1336 | Cisco EPC 3928 - Multiple Vulnerabilities | epc3928 firmware | Attack Blocked by Atomicorp | 333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648 |
| CVE-2017-14335 | Hanbanggaoke IP Camera - Arbitrary Password Change | hb7024xt firmware | Detected by Atomicorp | 345493 |
| CVE-2018-11222 | Pandora FMS <=7.0NG.722 - Remote Code Execution | pandora fms | Attack Blocked by Atomicorp | 390726 , 392647 |
| CVE-2019-11253 | Kubernetes API Server - YAML Parsing DoS (Billion Laughs) | kubernetes | Attack Blocked by Atomicorp | 391213 |
| CVE-2026-19913 | Kaltura HTML5 Video Player, html5lib library Improper Input Validation Vulnerability | Kaltura HTML5 Video Player, html5lib library | Attack Blocked by Atomicorp | 340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008 |
| CVE-2010-4297 | VMware Tools - Update OS Command Injection | workstation | Attack Blocked by Atomicorp | 392301 |
| CVE-2019-1936 | Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilities | integrated management controller supervisor | Attack Blocked by Atomicorp | 344362 , 344363 , 344370 , 345493 , 350147 , 360151 , 390724 , 390727 , 392301 , 392648 |
| CVE-2026-27891 | Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism | facturascripts | Attack Blocked by Atomicorp | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-3576 | Planyo Online Reservation System <= 3.0 - Arbitrary File Read | Planyo online reservation system | Attack Blocked by Atomicorp | 340165 , 344360 , 347009 |
| CVE-2026-56722 | Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI | dompdf | Attack Blocked by Atomicorp | 344360 , 390709 |
| CVE-2026-34442 | FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout | freescout | Attack Blocked by Atomicorp | 340165 , 344365 |
| CVE-2012-4982 | Forescout CounterACT 6.3.4.1 - Open Redirect | counteract | Attack Blocked by Atomicorp | 340162 , 340163 |
| CVE-2012-6499 | WordPress Plugin Age Verification v0.4 - Open Redirect | age verification | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-63428 | HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's dec | heyform | Attack Blocked by Atomicorp | 333140 , 333141 , 340095 , 342259 , 350147 , 350148 |
| CVE-2026-34959 | Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix | adminer | Attack Blocked by Atomicorp | 340165 , 344365 |
| CVE-2026-73845 | CKAN MCP Server: MQA server allowlist bypass via unanchored regex (isValidMqaServer) | ckan-mcp-server | Attack Blocked by Atomicorp | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2014-0865 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | Attack Blocked by Atomicorp | 392301 |
| CVE-2014-0868 | IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilities | algo credit limits | Attack Blocked by Atomicorp | 392301 |
| CVE-2026-16434 | Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass | adminer | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 , 390719 |
| CVE-2026-55554 | Dompdf: Chroot Validation Bypass | dompdf | Attack Blocked by Atomicorp | 344360 , 390709 |
| CVE-2025-8266 | ChanCMS <= 3.1. - Remote Code Execution | chancms | Attack Blocked by Atomicorp | 345240 , 380026 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 311235 | Active | disruptive (deny) |
| 312657 | Active | disruptive (deny) |
| 320464 | Active | disruptive (deny) |
| 320465 | Active | disruptive (deny) |
| 330791 | Active | disruptive (deny) |
| 330925 | Active | disruptive (deny) |
| 333140 | Active | disruptive (deny) |
| 333141 | Active | disruptive (deny) |
| 337109 | Active | disruptive (deny) |
| 337110 | Active | disruptive (deny) |
| 337207 | Active | disruptive (deny) |
| 337209 | Active | disruptive (deny) |
| 337211 | Active | disruptive (deny) |
| 337218 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340095 | Active | disruptive (deny) |
| 340099 | Active | disruptive (deny) |
| 340147 | Active | disruptive (deny) |
| 340148 | Active | disruptive (deny) |
| 340149 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340162 | Active | disruptive (deny) |
| 340163 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 340193 | Active | disruptive (deny) |
| 341099 | Active | disruptive (deny) |
| 341245 | Active | disruptive (deny) |
| 341256 | Active | disruptive (deny) |
| 342259 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344362 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 344380 | Active | disruptive (deny) |
| 344382 | Active | disruptive (deny) |
| 344385 | Active | disruptive (deny) |
| 345115 | Active | disruptive (deny) |
| 345117 | Active | disruptive (deny) |
| 345118 | Active | disruptive (deny) |
| 345240 | Active | disruptive (deny) |
| 345493 | Active | non-disruptive (pass) |
| 346755 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 347198 | Active | disruptive (deny) |
| 350147 | Active | disruptive (deny) |
| 350148 | Active | disruptive (deny) |
| 351000 | Active | disruptive (deny) |
| 360151 | Active | disruptive (deny) |
| 377360 | Active | non-disruptive (pass) |
| 380026 | Active | disruptive (deny) |
| 390109 | Active | disruptive (deny) |
| 390613 | Active | disruptive (deny) |
| 390614 | Active | disruptive (deny) |
| 390704 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 390719 | Active | disruptive (deny) |
| 390722 | Active | disruptive (deny) |
| 390724 | Active | disruptive (deny) |
| 390726 | Active | disruptive (deny) |
| 390727 | Active | disruptive (deny) |
| 390904 | Active | disruptive (deny) |
| 391213 | Active | disruptive (deny) |
| 392301 | Active | disruptive (deny) |
| 392647 | Active | disruptive (deny) |
| 392648 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 398008 | Active | non-disruptive (pass) |
| 398021 | Active | disruptive (deny) |
| 398022 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-10 (opens in a new tab) , CAPEC-101 (opens in a new tab) , CAPEC-104 (opens in a new tab) , CAPEC-108 (opens in a new tab) , CAPEC-109 (opens in a new tab) , CAPEC-110 (opens in a new tab) , CAPEC-120 (opens in a new tab) , CAPEC-13 (opens in a new tab) , CAPEC-135 (opens in a new tab) , CAPEC-136 (opens in a new tab) , CAPEC-14 (opens in a new tab) , CAPEC-153 (opens in a new tab) , CAPEC-182 (opens in a new tab) , CAPEC-209 (opens in a new tab) , CAPEC-22 (opens in a new tab) , CAPEC-23 (opens in a new tab) , CAPEC-230 (opens in a new tab) , CAPEC-231 (opens in a new tab) , CAPEC-24 (opens in a new tab) , CAPEC-250 (opens in a new tab) , CAPEC-261 (opens in a new tab) , CAPEC-267 (opens in a new tab) , CAPEC-28 (opens in a new tab) , CAPEC-3 (opens in a new tab) , CAPEC-31 (opens in a new tab) , CAPEC-42 (opens in a new tab) , CAPEC-43 (opens in a new tab) , CAPEC-45 (opens in a new tab) , CAPEC-46 (opens in a new tab) , CAPEC-47 (opens in a new tab) , CAPEC-473 (opens in a new tab) , CAPEC-52 (opens in a new tab) , CAPEC-53 (opens in a new tab) , CAPEC-588 (opens in a new tab) , CAPEC-63 (opens in a new tab) , CAPEC-64 (opens in a new tab) , CAPEC-664 (opens in a new tab) , CAPEC-67 (opens in a new tab) , CAPEC-7 (opens in a new tab) , CAPEC-71 (opens in a new tab) , CAPEC-72 (opens in a new tab) , CAPEC-73 (opens in a new tab) , CAPEC-78 (opens in a new tab) , CAPEC-79 (opens in a new tab) , CAPEC-8 (opens in a new tab) , CAPEC-80 (opens in a new tab) , CAPEC-81 (opens in a new tab) , CAPEC-83 (opens in a new tab) , CAPEC-85 (opens in a new tab) , CAPEC-88 (opens in a new tab) , CAPEC-9 (opens in a new tab)