On this page

CWE-20: Improper Input Validation

Weakness Summary

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

  • Canonical source: MITRE CWE-20 (opens in a new tab)
  • Published Atomicorp CVE observations: 72
  • Distinct affected products in those observations: 62
  • Active Atomicorp rules associated with this weakness: 76

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2009-0545ZeroShell <= 1.0beta11 Remote Code ExecutionzeroshellAttack Blocked by Atomicorp312657 , 340007 , 340029 , 344360 , 344370 , 347009 , 390709
CVE-2021-44228Apache Log4j2 Remote Code Injectionlog4jAttack Blocked by Atomicorp345115 , 345117 , 345118 , 393655
CVE-2024-22476Intel Neural Compressor <2.5.0 - SQL InjectionIntel(R) Neural Compressor softwareAttack Blocked by Atomicorp341245
CVE-2026-47668DbGate - Remote Code Execution via Anonymous JWTdbgateAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 360151 , 380026
CVE-2010-4239Tiki Wiki CMS Groupware 5.2 - Local File Inclusiontikiwiki cms/groupwareAttack Blocked by Atomicorp340007 , 390109
CVE-2014-3206Seagate BlackArmor NAS - Command Injectionblackarmor nas 220 firmwareAttack Blocked by Atomicorp311235 , 340014 , 340193 , 344364 , 344366
CVE-2015-4664Xceedium Xsuite - Multiple Vulnerabilitiesprivileged access managerAttack Blocked by Atomicorp320464 , 320465 , 333141 , 340023 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 344360 , 344361 , 344363 , 344370 , 346755 , 347198 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2016-5674NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesreadynas surveillanceAttack Blocked by Atomicorp344363 , 392301
CVE-2016-5675NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilitiesreadynas surveillanceAttack Blocked by Atomicorp392301
CVE-2016-6603WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilitieswebnms frameworkAttack Blocked by Atomicorp390727 , 392301 , 392648
CVE-2017-12611Apache Struts2 S2-053 - Remote Code ExecutionstrutsAttack Blocked by Atomicorp337207 , 337209 , 337211 , 337218 , 340014 , 340029 , 340193 , 344360 , 344362 , 344363 , 344370 , 347009
CVE-2017-16935Ametys CMS 4.0.2 - Password ResetametysAttack Blocked by Atomicorp345493 , 390724
CVE-2017-18349Fastjson Insecure Deserialization - Remote Code ExecutionfastjsonAttack Blocked by Atomicorp344380 , 344385 , 398008
CVE-2017-18580WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Executionshortcodes ultimateDetected by Atomicorp377360
CVE-2017-9791Apache Struts2 S2-053 - Remote Code ExecutionstrutsAttack Blocked by Atomicorp337207
CVE-2017-9811Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilitiesanti-virus for linux serverAttack Blocked by Atomicorp390704 , 390724
CVE-2018-11686FlexPaper/FlowPaper 2.3.6 - Remote Code ExecutionflowpaperAttack Blocked by Atomicorp340029 , 344361 , 344364
CVE-2018-20985WordPress Payeezy Pay <=2.97 - Local File Inclusionwp payeezy payAttack Blocked by Atomicorp392301
CVE-2018-7600Drupal - Remote Code ExecutiondrupalAttack Blocked by Atomicorp330791 , 340152
CVE-2020-13942Apache Unomi <1.5.2 - Remote Code ExecutionunomiAttack Blocked by Atomicorp340095
CVE-2021-21978VMware View Planner <4.6 SP1- Remote Code Executionview plannerAttack Blocked by Atomicorp330791 , 340007 , 340152
CVE-2022-24086Adobe Commerce (Magento) - Remote Code ExecutioncommerceAttack Blocked by Atomicorp344360 , 344370
CVE-2023-3710Honeywell PM43 Printers - Command Injectionpm43 firmwareAttack Blocked by Atomicorp344361 , 344363
CVE-2025-54123Hoverfly <= 1.11.3 - Remote Code ExecutionhoverflyAttack Blocked by Atomicorp344360
CVE-2026-19912Kaltura HTML5 Video Player, html5 library Arbitrary Code Execution VulnerabilityKaltura HTML5 Video Player, html5 libraryAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2026-35048Piwigo RCE via PHP Code Injection into Config File in InstallerPiwigoAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-49827WebErpMesv2 has Unauthenticated RCE via Unrestricted File Upload in HR Expense scan_file (CWE-434)WebErpMesv2Attack Blocked by Atomicorp351000
CVE-2026-53513Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationbetter-auth/ssoAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-54694NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeoverskills-serviceAttack Blocked by Atomicorp333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-44343WGDashboard < 4.3.2 - Unauthenticated File ReadwgdashboardAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709
CVE-2024-5276Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injectionfilecatalyst workflowAttack Blocked by Atomicorp341245
CVE-2026-41042Apache Gravitino < 1.2.1 - Unauthenticated Remote Code ExecutiongravitinoAttack Blocked by Atomicorp344370
CVE-2026-57499Liman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)coreAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2016-10960WordPress wSecure Lite < 2.4 - Remote Code ExecutionwsecureAttack Blocked by Atomicorp392301
CVE-2024-7340W&B Weave Server - Remote Arbitrary File Leak-Attack Blocked by Atomicorp347009
CVE-2026-24893openITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro ExpansionopenitcockpitAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-34197Apache ActiveMQ - Remote Code ExecutionactivemqAttack Blocked by Atomicorp330925 , 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-35031Jellyfin: Potential RCE via subtitle upload path traversal + .strm chainjellyfinAttack Blocked by Atomicorp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-40466Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport BypassactivemqAttack Blocked by Atomicorp330925 , 340162 , 340163
CVE-2026-45505Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia addNetworkConnector Discovery Wrapper BypassactivemqAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2025-34115OP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.phpOP5 MonitorAttack Blocked by Atomicorp340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" ComponeragflowAttack Blocked by Atomicorp340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-50553Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)note-markAttack Blocked by Atomicorp340007 , 344360 , 390709
CVE-2026-73658Trigger.dev: Cross-tenant object store read and write via URL path traversaltrigger.devAttack Blocked by Atomicorp347009
CVE-2017-15715Apache httpd <=2.4.29 - Arbitrary File Uploadhttp serverAttack Blocked by Atomicorp344365
CVE-2023-26067Lexmark Printers - Command Injectioncxtpc firmwareAttack Blocked by Atomicorp392301
CVE-2024-30188Apache DolphinScheduler >= 3.1.0, < 3.2.2 Resource File Read And WritedolphinschedulerAttack Blocked by Atomicorp340162 , 340165 , 344360 , 347009 , 390726 , 392647
CVE-2026-42588Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnectoractivemqAttack Blocked by Atomicorp340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-69192ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trusip-addressAttack Blocked by Atomicorp337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2016-10956WordPress Mail Masta 1.0 - Local File Inclusionmail-mastaAttack Blocked by Atomicorp344360 , 347009 , 390709
CVE-2016-1328Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 firmwareAttack Blocked by Atomicorp333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2016-1336Cisco EPC 3928 - Multiple Vulnerabilitiesepc3928 firmwareAttack Blocked by Atomicorp333141 , 340147 , 340148 , 340149 , 341256 , 342259 , 344363 , 346755 , 350148 , 390726 , 392301 , 392647 , 392648
CVE-2017-14335Hanbanggaoke IP Camera - Arbitrary Password Changehb7024xt firmwareDetected by Atomicorp345493
CVE-2018-11222Pandora FMS <=7.0NG.722 - Remote Code Executionpandora fmsAttack Blocked by Atomicorp390726 , 392647
CVE-2019-11253Kubernetes API Server - YAML Parsing DoS (Billion Laughs)kubernetesAttack Blocked by Atomicorp391213
CVE-2026-19913Kaltura HTML5 Video Player, html5lib library Improper Input Validation VulnerabilityKaltura HTML5 Video Player, html5lib libraryAttack Blocked by Atomicorp340014 , 340023 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 390613 , 390614 , 390722 , 398008
CVE-2010-4297VMware Tools - Update OS Command InjectionworkstationAttack Blocked by Atomicorp392301
CVE-2019-1936Cisco UCS Director_ Cisco Integrated Management Controller Supervisor and Cisco UCS Director Express for Big Data - Multiple Vulnerabilitiesintegrated management controller supervisorAttack Blocked by Atomicorp344362 , 344363 , 344370 , 345493 , 350147 , 360151 , 390724 , 390727 , 392301 , 392648
CVE-2026-27891Remote Code Execution (RCE) via Zip Slip in Plugin Upload MechanismfacturascriptsAttack Blocked by Atomicorp340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-3576Planyo Online Reservation System <= 3.0 - Arbitrary File ReadPlanyo online reservation systemAttack Blocked by Atomicorp340165 , 344360 , 347009
CVE-2026-56722Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URIdompdfAttack Blocked by Atomicorp344360 , 390709
CVE-2026-34442FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScoutfreescoutAttack Blocked by Atomicorp340165 , 344365
CVE-2012-4982Forescout CounterACT 6.3.4.1 - Open RedirectcounteractAttack Blocked by Atomicorp340162 , 340163
CVE-2012-6499WordPress Plugin Age Verification v0.4 - Open Redirectage verificationAttack Blocked by Atomicorp392301
CVE-2026-63428HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's decheyformAttack Blocked by Atomicorp333140 , 333141 , 340095 , 342259 , 350147 , 350148
CVE-2026-34959Adminer before 5.5.0 Open Redirect via X-Forwarded-PrefixadminerAttack Blocked by Atomicorp340165 , 344365
CVE-2026-73845CKAN MCP Server: MQA server allowlist bypass via unanchored regex (isValidMqaServer)ckan-mcp-serverAttack Blocked by Atomicorp337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2014-0865IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limitsAttack Blocked by Atomicorp392301
CVE-2014-0868IBM Algorithmics RICOS 4.5.0 < 4.7.0 - Multiple Vulnerabilitiesalgo credit limitsAttack Blocked by Atomicorp392301
CVE-2026-16434Adminer before 5.5.1 X-Forwarded-Prefix Backslash BypassadminerAttack Blocked by Atomicorp340007 , 344360 , 347009 , 390709 , 390719
CVE-2026-55554Dompdf: Chroot Validation BypassdompdfAttack Blocked by Atomicorp344360 , 390709
CVE-2025-8266ChanCMS <= 3.1. - Remote Code ExecutionchancmsAttack Blocked by Atomicorp345240 , 380026

Associated Atomicorp WAF Rules

RuleStatusBehavior
311235Activedisruptive (deny)
312657Activedisruptive (deny)
320464Activedisruptive (deny)
320465Activedisruptive (deny)
330791Activedisruptive (deny)
330925Activedisruptive (deny)
333140Activedisruptive (deny)
333141Activedisruptive (deny)
337109Activedisruptive (deny)
337110Activedisruptive (deny)
337207Activedisruptive (deny)
337209Activedisruptive (deny)
337211Activedisruptive (deny)
337218Activedisruptive (deny)
340007Activedisruptive (deny)
340014Activedisruptive (deny)
340023Activedisruptive (deny)
340029Activedisruptive (deny)
340095Activedisruptive (deny)
340099Activedisruptive (deny)
340147Activedisruptive (deny)
340148Activedisruptive (deny)
340149Activedisruptive (deny)
340152Activedisruptive (deny)
340162Activedisruptive (deny)
340163Activedisruptive (deny)
340165Activedisruptive (deny)
340193Activedisruptive (deny)
341099Activedisruptive (deny)
341245Activedisruptive (deny)
341256Activedisruptive (deny)
342259Activedisruptive (deny)
344360Activedisruptive (deny)
344361Activedisruptive (deny)
344362Activedisruptive (deny)
344363Activedisruptive (deny)
344364Activedisruptive (deny)
344365Activedisruptive (deny)
344366Activedisruptive (deny)
344370Activedisruptive (deny)
344380Activedisruptive (deny)
344382Activedisruptive (deny)
344385Activedisruptive (deny)
345115Activedisruptive (deny)
345117Activedisruptive (deny)
345118Activedisruptive (deny)
345240Activedisruptive (deny)
345493Activenon-disruptive (pass)
346755Activedisruptive (deny)
347009Activedisruptive (deny)
347198Activedisruptive (deny)
350147Activedisruptive (deny)
350148Activedisruptive (deny)
351000Activedisruptive (deny)
360151Activedisruptive (deny)
377360Activenon-disruptive (pass)
380026Activedisruptive (deny)
390109Activedisruptive (deny)
390613Activedisruptive (deny)
390614Activedisruptive (deny)
390704Activedisruptive (deny)
390709Activedisruptive (deny)
390719Activedisruptive (deny)
390722Activedisruptive (deny)
390724Activedisruptive (deny)
390726Activedisruptive (deny)
390727Activedisruptive (deny)
390904Activedisruptive (deny)
391213Activedisruptive (deny)
392301Activedisruptive (deny)
392647Activedisruptive (deny)
392648Activedisruptive (deny)
393655Activedisruptive (deny)
398008Activenon-disruptive (pass)
398021Activedisruptive (deny)
398022Activedisruptive (deny)

MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:

CAPEC-10 (opens in a new tab) , CAPEC-101 (opens in a new tab) , CAPEC-104 (opens in a new tab) , CAPEC-108 (opens in a new tab) , CAPEC-109 (opens in a new tab) , CAPEC-110 (opens in a new tab) , CAPEC-120 (opens in a new tab) , CAPEC-13 (opens in a new tab) , CAPEC-135 (opens in a new tab) , CAPEC-136 (opens in a new tab) , CAPEC-14 (opens in a new tab) , CAPEC-153 (opens in a new tab) , CAPEC-182 (opens in a new tab) , CAPEC-209 (opens in a new tab) , CAPEC-22 (opens in a new tab) , CAPEC-23 (opens in a new tab) , CAPEC-230 (opens in a new tab) , CAPEC-231 (opens in a new tab) , CAPEC-24 (opens in a new tab) , CAPEC-250 (opens in a new tab) , CAPEC-261 (opens in a new tab) , CAPEC-267 (opens in a new tab) , CAPEC-28 (opens in a new tab) , CAPEC-3 (opens in a new tab) , CAPEC-31 (opens in a new tab) , CAPEC-42 (opens in a new tab) , CAPEC-43 (opens in a new tab) , CAPEC-45 (opens in a new tab) , CAPEC-46 (opens in a new tab) , CAPEC-47 (opens in a new tab) , CAPEC-473 (opens in a new tab) , CAPEC-52 (opens in a new tab) , CAPEC-53 (opens in a new tab) , CAPEC-588 (opens in a new tab) , CAPEC-63 (opens in a new tab) , CAPEC-64 (opens in a new tab) , CAPEC-664 (opens in a new tab) , CAPEC-67 (opens in a new tab) , CAPEC-7 (opens in a new tab) , CAPEC-71 (opens in a new tab) , CAPEC-72 (opens in a new tab) , CAPEC-73 (opens in a new tab) , CAPEC-78 (opens in a new tab) , CAPEC-79 (opens in a new tab) , CAPEC-8 (opens in a new tab) , CAPEC-80 (opens in a new tab) , CAPEC-81 (opens in a new tab) , CAPEC-83 (opens in a new tab) , CAPEC-85 (opens in a new tab) , CAPEC-88 (opens in a new tab) , CAPEC-9 (opens in a new tab)