Atomicorp WAF Research Notes
Research Update - 2026-07-21
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
- CVE-2005-3344 - Horde Groupware Unauthenticated Admin Access - rules observed: 920420, 949110, 980170
- CVE-2022-22947 - Spring Cloud Gateway Code Injection - rules observed: 911100, 949110, 980170
- CVE-2023-27482 - Home Assistant Supervisor - Authentication Bypass - rules observed: 930100, 949110, 980170
- CVE-2024-3400 - GlobalProtect - OS Command Injection - rules observed: 930100, 930110, 949110, 980170
- CVE-2025-0108 - PAN-OS Management Interface - Path Confusion to Authentication Bypass - rules observed: 930100, 949110, 980170
- CVE-2025-34035 - EnGenius EnShare IoT Gigabit Cloud Service 1.4.11 Root Remote Code Execution - rules observed: 942100, 949110, 980170
- CVE-2025-47916 - Invision Community <=5.0.6 Unauthenticated RCE via Template Injection - rules observed: 932235, 932260, 933150, 949110, 980170
- CVE-2026-48282 - Adobe ColdFusion - RDS Arbitrary File Write - rules observed: 920420, 949110, 980170
- CVE-2023-48777 - WordPress Elementor 3.18.1 - File Upload/Remote Code Execution - rules observed: 377360
- CVE-2025-30220 - GeoServer WFS - XXE Processing Vulnerability - rules observed: 932260, 949110, 980170
- CVE-2015-7450 - IBM WebSphere Java Object Deserialization - Remote Code Execution - rules observed: 944130, 949110, 980170
- CVE-2016-7552 - Trend Micro Threat Discovery Appliance 2.6.1062r1 - Authentication Bypass - rules observed: 930100, 930110, 949110, 980170
- CVE-2016-9682 - Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection - rules observed: 930120, 949110, 980170
- CVE-2017-11444 - Subrion CMS <4.1.5.10 - SQL Injection - rules observed: 942100, 942151, 942190, 949110, 980170
- CVE-2017-12149 - Jboss Application Server - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2017-15944 - Palo Alto Network PAN-OS - Remote Code Execution - rules observed: 942540, 949110, 980170
- CVE-2018-1217 - Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control - rules observed: 920420, 944130, 949110, 980170
- CVE-2018-12463 - Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection - rules observed: 920470, 980170
- CVE-2018-14933 - NUUO NVRmini - Remote Command Execution - rules observed: 942540, 949110, 980170
- CVE-2018-19127 - PHPCMS 2008 - Remote Code Execution via Template Injection - rules observed: 930100, 930110, 933160, 942151, 949110, 980170
- CVE-2018-8823 - PrestaShop Responsive Mega Menu Module - Remote Code Execution - rules observed: 933160, 942100, 942151, 949110, 980170
- CVE-2019-11580 - Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution - rules observed: 920420, 920450, 949110, 980170
- CVE-2019-12990 - Citrix SD-WAN Center - Local File Inclusion - rules observed: 930100, 930110, 949110, 980170
- CVE-2019-16057 - D-Link DNS-320 - Remote Code Execution - rules observed: 932230, 932250, 949110, 980170
- CVE-2019-16759 - vBulletin 5.0.0-5.5.4 - Remote Command Execution - rules observed: 933160, 942100, 942151, 949110, 980170
- CVE-2019-17662 - ThinVNC 1.0b1 - Authentication Bypass - rules observed: 920440, 980170
- CVE-2019-2725 - Oracle WebLogic Server - Remote Command Execution - rules observed: 944130, 949110, 980170
- CVE-2019-5127 - YouPHPTube Encoder 2.3 - Remote Command Injection - rules observed: 932260, 949110, 980170
- CVE-2019-5128 - YouPHPTube Encoder - Arbitrary File Write - rules observed: 932260, 949110, 980170
- CVE-2019-5129 - YouPHPTube Encoder 2.3 - Command Injection - rules observed: 932260, 949110, 980170
- CVE-2019-7238 - Sonatype Nexus Repository Manager <3.15.0 - Remote Code Execution - rules observed: 944130, 949110, 980170
- CVE-2020-11975 - Apache Unomi - Remote Code Execution - rules observed: 944100, 944110, 944130, 949110, 980170
- CVE-2020-14882 - Oracle Weblogic Server - Remote Command Execution - rules observed: 930100, 949110, 980170
- CVE-2020-15505 - MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2020-19625 - Gridx 1.3 - Remote Code Execution - rules observed: 933160, 942100, 942151, 949110, 980170
- CVE-2020-20601 - ThinkCMF X2.2.2 - Remote Code Execution - rules observed: 933100, 933160, 942151, 949110, 980170
- CVE-2020-5847 - UnRaid <=6.80 - Remote Code Execution - rules observed: 933100, 933160, 942151, 949110, 980170
- CVE-2020-6637 - OpenSIS 7.3 - SQL Injection - rules observed: 942100, 949110, 980170
- CVE-2020-9757 - Craft CMS < 3.3.0 - Server-Side Template Injection - rules observed: 934200, 949110, 980170
- CVE-2021-21805 - Advantech R-SeeNet 2.4.12 - OS Command Injection - rules observed: 932380, 949110, 980170
- CVE-2021-24215 - Controlled Admin Access WordPress Plugin <= 1.4.0 - Improper Access Control & Privilege Escalation - rules observed: 377360
- CVE-2021-25032 - PublishPress Capabilities < 2.3.1 - Missing Authorization - rules observed: 931100, 949110, 980170
- CVE-2021-26084 - Confluence Server - Remote Code Execution - rules observed: 920540, 934200, 949110, 980170
- CVE-2021-27561 - YeaLink DM 3.6.0.20 - Remote Command Injection - rules observed: 931100, 932160, 934110, 949110, 980170
- CVE-2021-29203 - HPE Edgeline Infrastructure Manager <1.22 - Authentication Bypass - rules observed: 911100, 949110, 980170
- CVE-2021-30461 - VoipMonitor <24.61 - Remote Code Execution - rules observed: 933160, 949110, 980170
- CVE-2021-34427 - Eclipse BIRT Viewer - Remote Code Execution - rules observed: 934200, 949110, 980170
- CVE-2021-34621 - WordPress ProfilePress 3.0.0-3.1.3 - Admin User Creation Weakness - rules observed: 377360, 931100, 949110, 980170
- CVE-2021-35064 - Kramer VIAware - Privilege Escalation and Remote Code Execution - rules observed: 930120, 933100, 933160, 942151, 949110, 980170
- CVE-2021-35464 - ForgeRock OpenAM <7.0 - Remote Code Execution - rules observed: 930110, 949110, 980170
- CVE-2021-36356 - Kramer VIAware - Remote Code Execution - rules observed: 930120, 933100, 933160, 942151, 949110, 980170
- CVE-2021-37415 - Zoho ManageEngine ServiceDesk Plus - Authentication Bypass - rules observed: 930100, 930110, 949110, 980170
- CVE-2021-41653 - TP-Link - OS Command Injection - rules observed: 920420, 949110, 980170
- CVE-2021-4449 - ZoomSounds Plugin - Unauthenticated Arbitrary File Upload - rules observed: 392301, 920340, 980170
- CVE-2021-45420 - Emerson Dixell XWEB-500 - Arbitrary File Write - rules observed: 920420, 949110, 980170
- CVE-2021-45967 - Pascom CPS Server-Side Request Forgery - rules observed: 930110, 949110, 980170
- CVE-2021-46422 - SDT-CW3B1 1.1.0 - OS Command Injection - rules observed: 932130, 932160, 933135, 949110, 980170
- CVE-2022-1040 - Sophos XG115w Firewall 17.0.10 MR-10 - Authentication Bypass - rules observed: 920540, 949110, 980170
- CVE-2022-22965 - Spring - Remote Code Execution - rules observed: 944130, 949110, 980170
- CVE-2022-22972 - VMware Workspace ONE Access/Identity Manager/vRealize Automation - Authentication Bypass - rules observed: 931100, 949110, 980170
- CVE-2022-25061 - TP-Link TL-WR840N - Command Injection - rules observed: 920420, 949110, 980170
- CVE-2022-29009 - Cyber Cafe Management System 1.0 - SQL Injection - rules observed: 942100, 949110, 980170
- CVE-2022-29081 - Zoho ManageEngine - Access Control Bypass - rules observed: 930100, 930110, 949110, 980170
- CVE-2022-31161 - Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload - rules observed: 932260, 949110, 980170
- CVE-2022-31656 - VMware - Local File Inclusion - rules observed: 930130, 949110, 980170
- CVE-2022-32429 - MSNSwitch Firmware MNT.2408 - Authentication Bypass - rules observed: 920440, 949110, 980170
- CVE-2022-38130 - KeySight RF - smsRestoreDatabaseZip UNC path to Remote Code Execution - rules observed: 920420, 944130, 949110, 980170
- CVE-2022-3980 - Sophos Mobile managed on-premises - XML External Entity Injection - rules observed: 920420, 920470, 949110, 980170
- CVE-2022-39986 - RaspAP 2.8.7 - Unauthenticated Command Injection - rules observed: 930130, 949110, 980170
- CVE-2022-40684 - Fortinet - Authentication Bypass - rules observed: 911100, 949110, 980170
- CVE-2023-20887 - VMware VRealize Network Insight - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2023-25157 - GeoServer OGC Filter - SQL Injection - rules observed: 932260, 949110, 980170
- CVE-2023-33831 - FUXA - Unauthenticated Remote Code Execution - rules observed: 345240
- CVE-2023-35885 - Cloudpanel 2 < 2.3.1 - Remote Code Execution - rules observed: 933100, 933160, 942151, 949110, 980170
- CVE-2023-38992 - Jeecg-Boot v3.5.1 - SQL Injection - rules observed: 930130, 949110, 980170
- CVE-2023-42793 - JetBrains TeamCity < 2023.05.4 - Remote Code Execution - rules observed: 911100, 949110, 980170
- CVE-2023-43795 - GeoServer WPS - Server Side Request Forgery - rules observed: 913100, 949110, 980170
- CVE-2023-4450 - JeecgBoot JimuReport - Template injection - rules observed: 944130, 949110, 980170
- CVE-2023-47248 - PyArrow Flight RPC - Remote Code Execution - rules observed: 920420, 949110, 980170
- CVE-2023-47253 - Qualitor <= 8.20 - Remote Code Execution - rules observed: 933160, 949110, 980170
- CVE-2023-50578 - Mingsoft MCMS 5.2.9 - SQL Injection - rules observed: 933160, 942151, 949110, 980170
- CVE-2023-51467 - Apache OFBiz < 18.12.11 - Remote Code Execution - rules observed: 932235, 949110, 980170
- CVE-2024-0204 - Fortra GoAnywhere MFT - Authentication Bypass - rules observed: 930110, 941130, 949110, 980170
- CVE-2024-13159 - Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcardRecursive - rules observed: 930120, 949110, 980170
- CVE-2024-13160 - Ivanti EPM - Credential Coercion Vulnerability in GetHashForWildcard - rules observed: 930120, 949110, 980170
- CVE-2024-13161 - Ivanti EPM - Credential Coercion Vulnerability in GetHashForSingleFile - rules observed: 930120, 949110, 980170
- CVE-2024-13979 - St. Joe ERP system - SQL Injection - rules observed: 920420, 949110, 980170
- CVE-2024-27348 - Apache HugeGraph-Server - Remote Command Execution - rules observed: 944100, 944110, 944130, 949110, 980170
- CVE-2024-2862 - LG LED Assistant - Unauthenticated Password Reset - rules observed: 911100, 949110, 980170
- CVE-2024-2863 - LG LED Assistant - Thumbnail Path Traversal File Upload - rules observed: 930100, 930110, 949110, 980170
- CVE-2024-3234 - Chuanhu Chat - Directory Traversal - rules observed: 930100, 930110, 930130, 949110, 980170
- CVE-2024-35286 - Mitel MiCollab <= 9.8.0.33 - SQL Injection - rules observed: 930110, 942100, 942151, 942160, 949110, 980170
- CVE-2024-3605 - WP Hotel Booking <= 2.1.0 - SQL Injection - rules observed: 380122
- CVE-2024-36404 - GeoServer and GeoTools - Remote Code Execution - rules observed: 932260, 949110, 980170
- CVE-2024-37843 - Craft CMS <=v3.7.31 - SQL Injection - rules observed: 344378
- CVE-2024-38856 - Apache OFBiz - Improper Authorization & Remote Code Execution - rules observed: 920540, 949110, 980170
- CVE-2024-43965 - SendGrid for WordPress <= 1.4 - SQL Injection - rules observed: 931100, 949110, 980170
- CVE-2024-4885 - Progress Software WhatsUp Gold GetFileWithoutZip Directory Traversal - Remote Code Execution - rules observed: 930120, 942550, 949110, 980170
- CVE-2024-5276 - Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection - rules observed: 942100, 942350, 942360, 942540, 949110, 980170
- CVE-2024-5488 - SEOPress < 7.9 - Authentication Bypass - rules observed: 911100, 949110, 980170
- CVE-2024-55956 - Cleo Harmony < 5.8.0.24 - File Upload Vulnerability - rules observed: 920420, 949110, 980170
- CVE-2024-6028 - Quiz Maker <= 6.5.8.3 - SQL Injection - rules observed: 942160, 942230, 949110, 980170
- CVE-2024-7314 - AJ-Report < 1.4.1 - Remote Code Execution - rules observed: 944100, 944110, 944130, 949110, 980170
- CVE-2025-11833 - Post SMTP <= 3.6.0 - Email Log Disclosure - rules observed: 377360
- CVE-2025-1302 - JSONPath Plus < 10.3.0 - Remote Code Execution - rules observed: 345240
- CVE-2025-1562 - Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control - rules observed: 377360
- CVE-2025-22952 - Elestio Memos <= v0.24.0 - Server-Side Request Forgery - rules observed: 934110, 949110, 980170
- CVE-2025-36604 - Dell UnityVSA < 5.5 - Remote Command Injection - rules observed: 930110, 933135, 949110, 980170
- CVE-2025-4380 - Ads Pro Plugin <= 4.89 - Local File Inclusion - rules observed: 930110, 949110, 980170
- CVE-2025-4632 - Samsung MagicINFO 9 Server - File Upload & Remote Code Execution - rules observed: 920420, 930100, 930110, 949110, 980170
- CVE-2025-54123 - Hoverfly <= 1.11.3 - Remote Code Execution - rules observed: 911100, 949110, 980170
- CVE-2025-5569 - IdeaCMS <= 1.7 - SQL Injection - rules observed: 933160, 942100, 942151, 949110, 980170
- CVE-2025-61882 - Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Execution - rules observed: 920420, 930100, 930110, 949110, 980170
- CVE-2025-64446 - FortiWeb - Authentication Bypass - rules observed: 930100, 930110, 949110, 980170
- CVE-2025-66516 - Apache Tika - XML External Entity Injection - rules observed: 911100, 920420, 949110, 980170
- CVE-2025-67303 - ComfyUI-Manager < 3.38 - Configuration Overwrite - rules observed: 920420, 920440, 930130, 980170
- CVE-2025-54782 - NestJS DevTools Integration - Remote Code Execution - rules observed: 345240, 920420, 980170
- CVE-2026-41940 - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection - rules observed: 377364
- CVE-2026-48313 - ColdFusion - Path Traversal - rules observed: 920420, 949110, 980170
- CVE-2026-27971 - Qwik - Unauthenticated RCE via server$ Deserialization - rules observed: 920420, 949110, 980170
- CVE-2020-25762 - Seat Reservation System 1.0 - Unauthenticated SQL Injection - rules observed: 932235, 932260, 949110, 980170
- CVE-2021-21351 - XStream <1.4.16 - Remote Code Execution - rules observed: 930110, 944130, 949110, 980170
- CVE-2021-46424 - Telesquare TLR-2005KSH 1.0.0 - Arbitrary File Delete - rules observed: 911100, 949110, 980170
- CVE-2023-29919 - SolarView Compact <= 6.00 - Local File Inclusion - rules observed: 920250, 980170
- CVE-2023-47873 - WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload - rules observed: 377360
- CVE-2024-21887 - Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) - Command Injection - rules observed: 930100, 930110, 949110, 980170
- CVE-2024-36104 - Apache OFBiz - Directory Traversal & Remote Code Execution - rules observed: 920540, 949110, 980170
- CVE-2024-4180 - The Events Calendar < 6.4.0.1 - Cross-site Scripting - rules observed: 941100, 941160, 941180, 941390, 949110, 980170
- CVE-2024-48914 - Vendure - Arbitrary File Read - rules observed: 930100, 930110, 930130, 949110, 980170
- CVE-2025-13652 - WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL Injection - rules observed: 377360
- CVE-2025-49029 - WordPress Custom Login And Signup Widget Plugin <= 1.0 - Arbitrary Code Execution - rules observed: 377360, 933100, 933130, 933160, 949110, 980170
- CVE-2025-49493 - Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE) - rules observed: 920420, 949110, 980170
- CVE-2025-55747 - XWiki Platform - Information Disclosure - rules observed: 920440, 930130, 980170
- CVE-2025-23061 - Mongoose - NoSQL Injection - rules observed: 942290, 949110, 980170
- CVE-2025-6204 - DELMIA Apriso - Command Injection - rules observed: 941100, 941130, 949110, 980170
- CVE-2017-18580 - WordPress Shortcodes Ultimate <= 5.0.0 - Authenticated Remote Code Execution - rules observed: 377360
- CVE-2018-7765 - Schneider Electric U.motion Builder - SQL Injection - rules observed: 942100, 949110, 980170
- CVE-2020-9043 - WordPress wpCentral <1.5.1 - Information Disclosure - rules observed: 377360
- CVE-2021-24347 - WordPress SP Project & Document Manager <4.22 - Authenticated Shell Upload - rules observed: 377360
- CVE-2021-25082 - WordPress Popup Builder < 4.0.7 - Remote Code Execution - rules observed: 377360
- CVE-2021-25646 - Apache Druid - Remote Code Execution - rules observed: 944100, 944110, 944130, 949110, 980170
- CVE-2021-29505 - XStream <1.4.17 - Remote Code Execution - rules observed: 944130, 949110, 980170
- CVE-2021-46398 - FileBrowser 2.17.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution (RCE) - rules observed: 920420, 949110, 980170
- CVE-2022-0439 - Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injection - rules observed: 377360
- CVE-2022-1329 - Elementor Website Builder - Remote Code Execution - rules observed: 377360
- CVE-2022-1883 - Terraboard <2.2.0 - SQL Injection - rules observed: 942100, 942151, 942160, 942280, 949110, 980170
- CVE-2023-32749 - Pydio Cells 4.1.2 - Unauthorised Role Assignments - rules observed: 911100, 949110, 980170
- CVE-2024-0692 - SolarWinds Security Event Manager - Unauthenticated RCE - rules observed: 920420, 949110, 980170
- CVE-2024-25852 - Linksys RE7000 - Command Injection - rules observed: 911100, 949110, 980170
- CVE-2024-7399 - Samsung MagicINFO 9 Server 21.1050.0 - Remote Code Execution - rules observed: 920420, 930100, 930110, 949110, 980170
- CVE-2025-11307 - WP Google Maps < 9.0.48 - Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2025-2075 - Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation - rules observed: 377360
- CVE-2025-5961 - WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload - rules observed: 377360
- CVE-2025-6205 - DELMIA Apriso - Broken Access Control - rules observed: 941100, 941130, 949110, 980170
- CVE-2025-68645 - Zimbra Collaboration - Local File Inclusion - rules observed: 930120, 949110, 980170
- CVE-2026-40466 - Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypass - rules observed: 944130, 949110, 980170
- CVE-2023-41954 - ProfilePress <= 4.13.1 — Unauthenticated Privilege Escalation - rules observed: 931100, 949110, 980170
- CVE-2024-36117 - Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File Read - rules observed: 920440, 980170
- CVE-2025-64328 - FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command Injection - rules observed: 930130, 949110, 980170
- CVE-2026-21859 - Mailpit < 1.28.3 - Server-Side Request Forgery - rules observed: 931100, 934110, 949110, 980170
- CVE-2021-39141 - XStream 1.4.18 - Remote Code Execution - rules observed: 930100, 930110, 932130, 932235, 944130, 949110, 980170
- CVE-2021-39146 - XStream 1.4.18 - Arbitrary Code Execution - rules observed: 930100, 930110, 944130, 949110, 980170
- CVE-2021-39152 - XStream <1.4.18 - Server-Side Request Forgery - rules observed: 930100, 930110, 949110, 980170
- CVE-2012-10018 - WordPress Mapplic <= 6.1 / Mapplic Lite <= 1.0 - Authenticated Stored XSS via SVG File Upload - rules observed: 377360
- CVE-2021-39341 - OptinMonster Plugin < 2.6.5 - Unprotected REST-API - rules observed: 920450, 949110, 980170
- CVE-2023-46805 - Ivanti ICS - Authentication Bypass - rules observed: 930100, 930110, 949110, 980170
- CVE-2025-58360 - GeoServer - XML External Entity Injection - rules observed: 920420, 949110, 980170
- CVE-2018-1335 - Apache Tika < 1.1.8 - Header Command Injection - rules observed: 340138, 911100, 920420, 920450, 980170
- CVE-2020-36836 - WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion - rules observed: 377360
- CVE-2022-31101 - Prestashop Blockwishlist 2.1.0 SQL Injection - rules observed: 930130, 949110, 980170
- CVE-2024-3656 - Keycloak < 24.0.5 - Broken Access Control - rules observed: 931100, 949110, 980170
- CVE-2026-1207 - Django RasterField - SQL Injection - rules observed: 942100, 949110, 980170
- CVE-2020-26258 - XStream <1.4.15 - Server-Side Request Forgery - rules observed: 944110, 949110, 980170
- CVE-2024-32399 - RaidenMAILD Mail Server v.4.9.4 - Path Traversal - rules observed: 920440, 930130, 980170
- CVE-2025-4123 - Grafana - XSS / Open Redirect / SSRF via Client Path Traversal - rules observed: 930100, 949110, 980170
- CVE-2014-7226 - Rejetto HTTP File Server (HFS) 2.3a/2.3b/2.3c - Remote Command Execution - rules observed: 920250, 980170
- CVE-2017-14335 - Hanbanggaoke IP Camera - Arbitrary Password Change - rules observed: 911100, 930120, 941100, 949110, 980170
- CVE-2018-0296 - Cisco ASA - Local File Inclusion - rules observed: 930100, 930110, 949110, 980170
- CVE-2018-7171 - TwonkyMedia Server 7.0.11-8.5 - Directory Traversal - rules observed: 930100, 930110, 949110, 980170
- CVE-2019-10266 - Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection - rules observed: 920420, 949110, 980170
- CVE-2019-11253 - Kubernetes API Server - YAML Parsing DoS (Billion Laughs) - rules observed: 920420, 949110, 980170
- CVE-2019-13608 - Citrix StoreFront Server - XML External Entity - rules observed: 920420, 949110, 980170
- CVE-2019-16758 - Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal - rules observed: 920440, 980170
- CVE-2019-20085 - TVT NVMS 1000 - Local File Inclusion - rules observed: 920440, 930130, 980170
- CVE-2019-6715 - W3 Total Cache 0.9.2.6-0.9.3 - Unauthenticated File Read / Directory Traversal - rules observed: 911100, 949110, 980170
- CVE-2019-8086 - Adobe Experience Manager - XML External Entity Injection - rules observed: 920540, 949110, 980170
- CVE-2019-8442 - Jira - Local File Inclusion - rules observed: 930130, 949110, 980170
- CVE-2019-9632 - ESAFENET CDG - Arbitrary File Download - rules observed: 930110, 930120, 949110, 980170
- CVE-2020-11732 - Media Library Assistant < 2.82 - Unauthenticated Limited Local File Inclusion - rules observed: 930120, 949110, 980170
- CVE-2020-12127 - WAVLINK WN530H4 M30H4.V5030.190403 - Information Disclosure - rules observed: 920440, 949110, 980170
- CVE-2020-15050 - Suprema BioStar <2.8.2 - Local File Inclusion - rules observed: 920440, 930130, 980170
- CVE-2020-17518 - Apache Flink 1.5.1 - Local File Inclusion - rules observed: 930100, 949110, 980170
- CVE-2020-24571 - NexusDB <4.50.23 - Local File Inclusion - rules observed: 920440, 930130, 980170
- CVE-2020-25780 - Commvault CommCell - Local File Inclusion - rules observed: 930120, 949110, 980170
- CVE-2020-3452 - Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion - rules observed: 930110, 949110, 980170
- CVE-2021-24170 - User Profile Picture < 2.5.0 - Sensitive Information Disclosure - rules observed: 377360
- CVE-2021-24644 - Images to WebP < 1.9 - Authenticated Local File Inclusion - rules observed: 377360
- CVE-2021-26294 - AfterLogic Aurora and WebMail Pro < 7.7.9 - Information Disclosure - rules observed: 930100, 930110, 949110, 980170
- CVE-2021-27315 - Doctor Appointment System 1.0 - SQL Injection - rules observed: 942100, 942160, 949110, 980170
- CVE-2021-30497 - Ivanti Avalanche 6.3.2 - Local File Inclusion - rules observed: 930120, 949110, 980170
- CVE-2021-32789 - WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection - rules observed: 942270, 949110, 980170
- CVE-2021-36748 - PrestaHome Blog for PrestaShop <1.7.8 - SQL Injection - rules observed: 942100, 949110, 980170
- CVE-2021-37305 - Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure - rules observed: 930130, 949110, 980170
- CVE-2021-40856 - Auerswald COMfortel 1400/2600/3600 IP - Authentication Bypass - rules observed: 930100, 930110, 949110, 980170
- CVE-2021-41097 - Aurelia-Path < 1.1.7 - Prototype Pollution - rules observed: 934130, 949110, 980170
- CVE-2021-41381 - Payara Micro Community 5.2021.6 Directory Traversal - rules observed: 930130, 949110, 980170
- CVE-2021-44138 - Caucho Resin >=4.0.52 <=4.0.56 - Directory traversal - rules observed: 930130, 949110, 980170
- CVE-2021-45027 - Oliver 5 Library Server <8.00.008.053 - Local File Inclusion - rules observed: 930120, 949110, 980170
- CVE-2021-46418 - Telesquare TLR-2855KS6 - Arbitrary File Creation - rules observed: 911100, 949110, 980170
- CVE-2022-1713 - Drawio <18.0.4 - Server-Side Request Forgery - rules observed: 931100, 949110, 980170
- CVE-2022-24124 - Casdoor 1.13.0 - Unauthenticated SQL Injection - rules observed: 942100, 942151, 949110, 980170
- CVE-2022-25216 - DVDFab 12 Player/PlayerFab - Local File Inclusion - rules observed: 920440, 930130, 980170
- CVE-2022-29153 - HashiCorp Consul/Consul Enterprise - Server-Side Request Forgery - rules observed: 911100, 949110, 980170
- CVE-2022-31268 - Gitblit 1.9.3 - Local File Inclusion - rules observed: 930100, 930110, 930130, 949110, 980170
- CVE-2022-31847 - WAVLINK WN579 X3 M79X3.V5030.180719 - Information Disclosure - rules observed: 920440, 949110, 980170
- CVE-2022-34576 - WAVLINK WN535 G3 - Improper Access Control - rules observed: 920440, 949110, 980170
- CVE-2022-44356 - WAVLINK Quantum D4G (WL-WN531G3) - Information Disclosure - rules observed: 920440, 949110, 980170
- CVE-2022-45269 - Linx Sphere - Directory Traversal - rules observed: 920440, 980170
- CVE-2022-48165 - Wavlink - Improper Access Control - rules observed: 920440, 949110, 980170
- CVE-2023-26255 - STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion - rules observed: 930110, 930120, 949110, 980170
- CVE-2023-49103 - OwnCloud - Phpinfo Configuration - rules observed: 930130, 949110, 980170
- CVE-2023-5003 - Active Directory Integration WP Plugin < 4.1.10 - Log Disclosure - rules observed: 930130, 949110, 980170
- CVE-2023-6266 - WordPress Backup Migration <= 1.3.6 - Path Traversal - rules observed: 930110, 949110, 980170
- CVE-2024-2053 - Artica Proxy - Unauthenticated LFI - rules observed: 930100, 930110, 949110, 980170
- CVE-2024-28752 - Apache CXF < 4.0.4 - Aegis DataBinding SSRF / Local File Read - rules observed: 920420, 949110, 980170
- CVE-2024-36857 - Jan v0.4.12 ‘readFileSync’ - Path Traversal - rules observed: 920420, 949110, 980170
- CVE-2024-38653 - Ivanti Avalanche SmartDeviceServer - XML External Entity - rules observed: 911100, 980170
- CVE-2024-41713 - Mitel MiCollab - Authentication Bypass - rules observed: 930110, 949110, 980170
- CVE-2024-45293 - TablePress < 2.4.3 - XXE Injection - rules observed: 377360
- CVE-2024-57727 - SimpleHelp <= 5.5.7 - Unauthenticated Path Traversal - rules observed: 930100, 930110, 930130, 949110, 980170
- CVE-2025-2264 - Sante PACS Server.exe - Path Traversal Information Disclosure - rules observed: 920440, 980170
- CVE-2025-34038 - Fanwei e-cology - SQL Injection - rules observed: 942100, 949110, 980170
- CVE-2025-55749 - XWiki - Information Disclosure - rules observed: 930130, 949110, 980170
- CVE-2025-69200 - phpMyFAQ - Configuration Backup Disclosure - rules observed: 920420, 949110, 980170
- CVE-2026-33476 - SiYuan <= v3.6.1 - Path Traversal - rules observed: 930100, 930110, 949110, 980170
- CVE-2026-54066 - SiYuan <= 3.6.5 - Unauthenticated Path Traversal - rules observed: 930100, 949110, 980170
- CVE-2026-9282 - W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read - rules observed: 344360
- CVE-2017-3506 - Oracle Fusion Middleware Weblogic Server - Remote OS Command Execution - rules observed: 920600, 944130, 949110, 980170
- CVE-2024-27199 - TeamCity < 2023.11.4 - Authentication Bypass - rules observed: 930100, 930110, 949110, 980170
- CVE-2024-33288 - Prison Management System - SQL Injection Authentication Bypass - rules observed: 942100, 949110, 980170
- CVE-2024-9916 - HuangDou UTCMS V9 - OS Command Injection - rules observed: 932260, 949110, 980170
- CVE-2020-36731 - Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update - rules observed: 377360, 941100, 941110, 941160, 941180, 941390, 949110, 980170
- CVE-2021-24155 - WordPress BackupGuard <1.6.0 - Authenticated Arbitrary File Upload - rules observed: 377360
- CVE-2021-24970 - WordPress All-In-One Video Gallery <2.5.0 - Local File Inclusion - rules observed: 377360, 930100, 930110, 949110, 980170
- CVE-2022-43769 - Hitachi Pentaho Business Analytics Server - Remote Code Execution - rules observed: 934200, 949110, 980170
- CVE-2023-0900 - AP Pricing Tables Lite <= 1.1.6 - SQL Injection - rules observed: 377360
- CVE-2023-3388 - Beautiful Cookie Consent Banner < 2.10.2 - Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2024-4439 - WordPress Core <6.5.2 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-4455 - YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-6753 - Social Auto Poster <= 5.3.14 - Stored Cross-Site Scripting - rules observed: 377360
- CVE-2024-8625 - WordPress TS Poll < 2.4.0 - SQL Injection - rules observed: 931100, 949110, 980170
- CVE-2024-10152 - Simple Certain Time to Show Content - Cross-Site Scripting - rules observed: 377360
- CVE-2024-12638 - Bulk Me Now! Plugin <= 2.0 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-12749 - WordPress Competition Form Plugin <= 2.0 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-12878 - Lazy Blocks <= 3.8.2 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13055 - Dyn Business Panel Plugin <= 1.0.0 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13094 - WP Triggers Lite - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13330 - JustRows WordPress - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13352 - Legull WordPress - Cross-Site Scripting - rules observed: 931100, 949110, 980170
- CVE-2024-13569 - WordPress Front End Users - Reflected XSS - rules observed: 377360
- CVE-2024-13625 - Tube Video Ads Lite - Reflected XSS - rules observed: 931100, 949110, 980170
- CVE-2024-39646 - WordPress Custom 404 Pro <= 3.11.1 - Reflected XSS - rules observed: 377360
- CVE-2024-5082 - Nexus Repository 2 - Remote Code Execution - rules observed: 911100, 980170
- CVE-2026-49069 - WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS) - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2020-9484 - Apache Tomcat Remote Command Execution - rules observed: 930100, 930110, 949110, 980170
- CVE-2025-1338 - NUUO Camera <=20250203 - OS Command Injection - rules observed: 930130, 949110, 980170
- CVE-2015-2755 - WordPress AB Google Map Travel <=3.4 - Stored Cross-Site Scripting - rules observed: 377360, 941100, 941110, 941160, 941180, 941390, 949110, 980170
- CVE-2024-8883 - Keycloak - Open Redirect - rules observed: 931100, 932130, 934110, 949110, 980170
- CVE-2009-3960 - Adobe (Multiple Products) - XML External Entity / XML Injection - rules observed: 920420, 949110, 980170
- CVE-2015-7780 - ManageEngine Firewall Analyzer <8.0 - Local File Inclusion - rules observed: 930120, 949110, 980170
- CVE-2019-5591 - FortiOS - Insecure LDAP Configuration Detection - rules observed: 920420, 949110, 980170
- CVE-2019-8451 - Jira <8.4.0 - Server-Side Request Forgery - rules observed: 931100, 949110, 980170
- CVE-2020-8615 - Wordpress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery - rules observed: 377360
- CVE-2022-1398 - External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request Forgery - rules observed: 377360
- CVE-2023-32750 - Pydio Cells 4.1.2 - Server-Side Request Forgery - rules observed: 911100, 949110, 980170
- CVE-2023-3345 - LMS by Masteriyo < 1.6.8 - Information Exposure - rules observed: 377360
- CVE-2023-41266 - Qlik Sense Enterprise - Path Traversal - rules observed: 930100, 930110, 949110, 980170
- CVE-2024-9765 - EKC Tournament Manager WordPress plugin - Path Traversal - rules observed: 377360
- CVE-2025-20362 - Cisco Secure Firewall ASA & FTD - Authentication Bypass - rules observed: 930100, 930110, 949110, 980170
- CVE-2025-2748 - Kentico Xperience CMS - Unauthenticated Stored XSS - rules observed: 920420, 949110, 980170
- CVE-2025-13418 - Responsive Pricing Table <= 5.1.12 - Cross-Site Scripting - rules observed: 377360
- CVE-2008-2052 - Bitrix Site Management 2.x - Open Redirect - rules observed: 920250, 931100, 949110, 980170
- CVE-2015-8350 - WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS - rules observed: 377360
- CVE-2016-10976 - Safe Editor Plugin < 1.2 - CSS/JS-injection - rules observed: 941180, 941390, 949110, 980170
- CVE-2017-20192 - Formidable Forms < 2.05.02 - Cross-Site Scripting - rules observed: 941100, 941160, 941180, 941390, 949110, 980170
- CVE-2017-3133 - Fortinet FortiOS < 5.6.0 - Cross-Site Scripting - rules observed: 920420, 949110, 980170
- CVE-2018-10141 - Palo Alto Networks PAN-OS GlobalProtect <8.1.4 - Cross-Site Scripting - rules observed: 941390, 942540, 949110, 980170
- CVE-2018-11133 - Quest KACE SMA /common/run_cross_report.php ‘fmt’ XSS - rules observed: 941180, 941390, 949110, 980170
- CVE-2018-14574 - Django - Open Redirect - rules observed: 920440, 949110, 980170
- CVE-2018-19386 - SolarWinds Database Performance Analyzer 11.1.457 - Cross-Site Scripting - rules observed: 941170, 941180, 941210, 941390, 949110, 980170
- CVE-2018-20367 - WSTMart 2.0.8 - Cross-Site Scripting - rules observed: 920600, 941100, 941120, 941160, 941390, 949110, 980170
- CVE-2019-10098 - Apache HTTP server v2.4.0 to v2.4.39 - Open Redirect - rules observed: 920440, 980170
- CVE-2019-11869 - WordPress Yuzo <5.12.94 - Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2019-14750 - osTicket < 1.12.1 - Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941390, 949110, 980170
- CVE-2019-17231 - WordPress OneTone theme <= 3.0.6 – Unauthenticated Stored XSS - rules observed: 934100, 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2019-7543 - KindEditor 4.1.11 - Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941180, 941390, 949110, 980170
- CVE-2019-9554 - Craft CMS 3.1.12 Pro - Cross-Site Scripting - rules observed: 941160, 941390, 942550, 949110, 980170
- CVE-2019-9955 - Zyxel - Cross-Site Scripting - rules observed: 941390, 942540, 949110, 980170
- CVE-2020-12704 - UliCMS 2020.1 - Persistent Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2020-12707 - LeptonCMS 4.5.0 - Persistent Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2020-14408 - Agentejo Cockpit 0.10.2 - Cross-Site Scripting - rules observed: 941180, 941390, 942540, 949110, 980170
- CVE-2020-15895 - D-Link DIR-816L 2.x - Cross-Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2020-17453 - WSO2 Carbon Management Console <=5.10 - Cross-Site Scripting - rules observed: 941180, 941390, 942540, 949110, 980170
- CVE-2020-8549 - WordPress Plugin Strong Testimonials 2.40.1 - Persistent Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2020-9036 - Jeedom <=4.0.38 - Cross-Site Scripting - rules observed: 941180, 941390, 942540, 949110, 980170
- CVE-2021-22122 - FortiWeb - Cross Site Scripting - rules observed: 941180, 941390, 942540, 949110, 980170
- CVE-2021-24165 - WordPress Ninja Forms <3.4.34 - Open Redirect - rules observed: 377360
- CVE-2021-24213 - GiveWP <= 2.9.7 - Cross-Site Scripting - rules observed: 377360
- CVE-2021-24286 - WordPress Plugin Redirect 404 to Parent 1.3.0 - Cross-Site Scripting - rules observed: 377360, 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-24287 - WordPress Select All Categories and Taxonomies <1.3.2 - Cross-Site Scripting - rules observed: 377360, 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-24351 - WordPress The Plus Addons for Elementor <4.1.12 - Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941180, 941390, 949110, 980170
- CVE-2021-24452 - WordPress W3 Total Cache <2.1.5 - Cross-Site Scripting - rules observed: 377360, 941180, 941390, 949110, 980170
- CVE-2021-24657 - Limit Login Attempts WordPress - Stored Cross-site Scripting - rules observed: 377360
- CVE-2021-24876 - Registrations for The Events Calendar < 2.7.5 - Authenticated Reflected Cross-Site Scripting - rules observed: 377360
- CVE-2021-24878 - SupportCandy < 2.2.7 - Reflected Cross-Site Scripting - rules observed: 941390, 949110, 980170
- CVE-2021-25099 - WordPress GiveWP <2.17.3 - Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941180, 941390, 949110, 980170
- CVE-2021-26812 - Moodle Jitsi Meet 2.7-2.8.3 - Cross-Site Scripting - rules observed: 931100, 941180, 941390, 949110, 980170
- CVE-2021-27695 - openMAINT openMAINT 2.1-3.3-b - ‘Multiple’ Persistent Cross-Site Scripting - rules observed: 911100, 949110, 980170
- CVE-2021-27909 - Mautic <3.3.4 - Cross-Site Scripting - rules observed: 941180, 941390, 942540, 949110, 980170
- CVE-2021-29622 - Prometheus - Open Redirect - rules observed: 920440, 949110, 980170
- CVE-2021-30151 - Sidekiq <=6.2.0 - Cross-Site Scripting - rules observed: 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-33904 - Accela Civic Platform <=21.1 - Cross-Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2021-37216 - QSAN Storage Manager <3.3.3 - Cross-Site Scripting - rules observed: 941110, 949110, 980170
- CVE-2021-40968 - Spotweb <= 1.5.1 - Cross Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-40969 - Spotweb <= 1.5.1 - Cross Site Scripting (Reflected) - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-40970 - Spotweb <= 1.5.1 - Cross Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-40971 - Spotweb <= 1.5.1 - Cross Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-40972 - Spotweb <= 1.5.1 - Cross Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-40973 - Spotweb <= 1.5.1 - Cross Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-41174 - Grafana 8.0.0 <= v.8.2.2 - Angularjs Rendering Cross-Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2021-42063 - SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scripting - rules observed: 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2021-42566 - myfactory FMS - Cross-Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2022-0189 - WordPress RSS Aggregator < 4.20 - Authenticated Cross-Site Scripting - rules observed: 377360, 921130, 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2022-0288 - WordPress Ad Inserter <2.7.10 - Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2022-0422 - WordPress White Label CMS <2.2.9 - Cross-Site Scripting - rules observed: 941390, 949110, 980170
- CVE-2022-0692 - Rudloff alltube prior to 3.0.1 - Open Redirect - rules observed: 920440, 949110, 980170
- CVE-2022-1597 - WordPress WPQA <5.4 - Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2022-1916 - WordPress Active Products Tables for WooCommerce <1.0.5 - Cross-Site Scripting - rules observed: 920540, 941100, 941110, 941160, 941180, 941390, 949110, 980170
- CVE-2022-24181 - PKP Open Journal Systems 2.4.8-3.3 - Cross-Site Scripting - rules observed: 941110, 949110, 980170
- CVE-2022-2627 - WordPress Newspaper < 12 - Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2022-28923 - Caddy 2.4.6 - Open Redirect - rules observed: 930100, 949110, 980170
- CVE-2022-29548 - WSO2 - Cross-Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2022-45365 - Stock Ticker <= 3.23.2 - Cross-Site-Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2023-0514 - Membership Database <= 1.0 - Cross-Site Scripting - rules observed: 377360, 941100, 941110, 941160, 941180, 941390, 949110, 980170
- CVE-2023-2272 - Tiempo.com <= 0.1.2 - Cross-Site Scripting - rules observed: 377360, 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2023-29506 - XWiki >= 13.10.8 - Cross-Site Scripting - rules observed: 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2023-37979 - Ninja Forms < 3.6.26 - Cross-Site Scripting - rules observed: 377360, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2023-40208 - Stock Ticker <= 3.23.2 - Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2023-44813 - mooSocial v.3.1.8 - Cross-Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2024-12724 - WP DeskLite - Reflected XSS - rules observed: 931100, 949110, 980170
- CVE-2024-12732 - AffiliateImporterEb <= 1.0.6 - Reflected XSS - rules observed: 377360
- CVE-2024-12734 - Advance Post Prefix WordPress plugin - Reflected XSS - rules observed: 377360
- CVE-2024-12737 - WP BASE Booking - Reflected XSS - rules observed: 377360
- CVE-2024-12873 - Custom Field Manager WordPress - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13112 - WP MediaTagger <= 4.1.1 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13114 - WP Projects Portfolio <= 3.0 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13219 - Privacy Policy Genius - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13220 - WordPress Google Map Professional - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13221 - Fantastic ElasticSearch Plugin <= 4.1.0 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13222 - WordPress User Messages <= 1.2.4 - Reflected XSS - rules observed: 931100, 949110, 980170
- CVE-2024-13224 - SlideDeck 1 Lite Content Slider - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13225 - ECT Home Page Products - Reflected XSS - rules observed: 377360
- CVE-2024-13226 - A5 Custom Login Page - Reflected XSS - rules observed: 377360
- CVE-2024-13325 - Glossy WordPress - Reflected XSS - rules observed: 377360
- CVE-2024-13326 - iBuildApp <= 0.2.0 - Reflected Cross-Site Scripting - rules observed: 377360
- CVE-2024-13327 - Musicbox WordPress - Reflected XSS - rules observed: 377360
- CVE-2024-13328 - Giga Messenger WordPress - Cross-Site Scripting - rules observed: 931100, 949110, 980170
- CVE-2024-13331 - WP Dream Carousel < 1.0.1b - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13492 - Guten Free Options - Cross Site Scripting - rules observed: 377360
- CVE-2024-13543 - Zarinpal Paid Download - Reflected XSS - rules observed: 377360
- CVE-2024-13570 - WordPress Stray Random Quotes <= 1.9.9 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13619 - LifterLMS < 8.0.1 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13628 - WP Pricing Table - Reflected XSS - rules observed: 377360
- CVE-2024-13630 - NewsTicker <= 1.0 - Reflected Cross-Site Scripting - rules observed: 377360
- CVE-2024-13634 - Post Sync Plugin <= 1.1 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-29138 - WordPress Restrict User Access <= 2.5 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-29792 - Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting - rules observed: 377360
- CVE-2024-30194 - Sunshine Photo Cart <= 3.1.1 - Reflected Cross-Site Scripting - rules observed: 377360
- CVE-2024-35627 - TileServer API - Cross Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2024-37261 - WP-Lister Lite for Amazon <= 2.6.16 - Cross-Site Scripting - rules observed: 377360, 941100, 941120, 941180, 941390, 949110, 980170
- CVE-2024-42852 - AcuToWeb server/10.5.0.7577c8b - Cross-Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2024-43971 - Sunshine Photo Cart <= 3.2.5 - Reflected Cross-Site Scripting - rules observed: 377360
- CVE-2025-4652 - Broadstreet WordPress plugin - Reflected XSS - rules observed: 377360
- CVE-2025-66472 - XWiki DeleteApplication - Cross-Site Scripting - rules observed: 932160, 941180, 941390, 942540, 949110, 980170
- CVE-2026-1296 - Frontend Post Submission Manager Lite <= 1.2.7 - Open Redirect - rules observed: 377360
- CVE-2026-34605 - SiYuan Note - Cross-Site Scripting - rules observed: 941100, 941130, 941160, 941180, 941390, 949110, 980170
- CVE-2025-62522 - Vite - Information Disclosure - rules observed: 930130, 949110, 980170
- CVE-2017-8295 - WordPress Core < 4.7.4 - Unauthorized Password Reset - rules observed: 377360
- CVE-2023-27624 - WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS - rules observed: 931100, 949110, 980170
- CVE-2017-14725 - WordPress < 4.8.2 - Authenticated Open Redirect - rules observed: 377360
- CVE-2017-17092 - WordPress < 4.9.1 - Authenticated JavaScript File Upload - rules observed: 377360
- CVE-2017-6340 - Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities - rules observed: 932230, 932250, 942360, 949110, 980170
- CVE-2018-16363 - WordPress File Manager < 3.0 - Cross-Site Scripting - rules observed: 377360
- CVE-2020-10385 - WordPress Plugin WPForms 1.5.8.2 - Persistent Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941390, 942550, 949110, 980170
- CVE-2020-15038 - Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting - rules observed: 941100, 941110, 941160, 941390, 949110, 980170
- CVE-2020-29233 - WonderCMS 3.1.3 - ‘content’ Persistent Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941390, 949110, 980170
- CVE-2021-33851 - WordPress Customize Login Image <3.5.3 - Cross-Site Scripting - rules observed: 377360
- CVE-2021-36873 - WordPress iQ Block Country <=1.2.11 - Cross-Site Scripting - rules observed: 377360
- CVE-2021-42053 - django-unicorn 0.35.3 - Stored Cross-Site Scripting (XSS) - rules observed: 920420, 949110, 980170
- CVE-2022-0765 - WordPress Loco Translate < 2.6.1 - Cross-Site Scripting - rules observed: 377360
- CVE-2022-3506 - WordPress Related Posts <2.1.3 - Stored Cross-Site Scripting - rules observed: 377360
- CVE-2022-40047 - Flatpress < v1.2.1 - Cross Site Scripting - rules observed: 941100, 941120, 941160, 941180, 941390, 949110, 980170
- CVE-2023-40355 - Axigen WebMail - Cross-Site Scripting - rules observed: 941180, 941390, 949110, 980170
- CVE-2023-7246 - System Dashboard < 2.8.10 - Cross-Site Scripting - rules observed: 377360, 941110, 949110, 980170
- CVE-2024-10146 - Simple File List < 6.1.13 - Reflected Cross-Site Scripting - rules observed: 377360
- CVE-2024-13097 - WP Finance Plugin <= 1.3.6 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13098 - WordPress Email Newsletter - Reflected XSS - rules observed: 377360
- CVE-2024-13099 - Widget4Call WordPress - Cross-Site Scripting - rules observed: 377360
- CVE-2024-3850 - Uniview NVR301-04S2-P4 - Cross-Site Scripting - rules observed: 941120, 941160, 949110, 980170
- CVE-2024-41819 - NoteMark < 0.13.0 - Stored XSS - rules observed: 911100, 920420, 949110, 980170
- CVE-2020-29453 - Jira Server Pre-Auth - Arbitrary File Retrieval (WEB-INF, META-INF) - rules observed: 930130, 949110, 980170
- CVE-2021-22017 - vCenter Server - Improper Access Control - rules observed: 930110, 949110, 980170
- CVE-2021-26085 - Atlassian Confluence Server - Local File Inclusion - rules observed: 930130, 949110, 980170
- CVE-2021-26086 - Atlassian Jira Limited - Local File Inclusion - rules observed: 930130, 949110, 980170
- CVE-2021-28164 - Eclipse Jetty - Information Disclosure - rules observed: 930130, 949110, 980170
- CVE-2021-28169 - Eclipse Jetty ConcatServlet - Information Disclosure - rules observed: 930120, 949110, 980170
- CVE-2022-3124 - Frontend File Manager < 21.3 - Unauthenticated File Renaming - rules observed: 930100, 930110, 949110, 980170
- CVE-2022-34049 - WAVLINK WN530HG4 - Improper Access Control - rules observed: 920440, 949110, 980170
- CVE-2023-36844 - Juniper Devices - Remote Code Execution - rules observed: 932235, 932260, 941130, 941170, 949110, 980170
- CVE-2024-21645 - pyload - Log Injection - rules observed: 931100, 949110, 980170
- CVE-2024-2473 - WPS Hide Login <= 1.9.15.2 - Login Page Disclosure - rules observed: 377360
- CVE-2024-50334 - Scoold < 1.64.0 - Authentication Bypass - rules observed: 911100, 920420, 949110, 980170
- CVE-2025-58751 - Vite Dev Server - Path Traversal - rules observed: 930130, 980170
- CVE-2025-9196 - Trinity Audio <= 5.21.0 - Information Exposure - rules observed: 930130, 949110, 980170
- CVE-2026-25527 - changedetection.io <= 0.52.9 - Unauthenticated Path Traversal - rules observed: 930100, 930110, 949110, 980170
- CVE-2013-3827 - Javafaces LFI - rules observed: 930110, 930130, 949110, 980170
- CVE-2014-4942 - WordPress EasyCart <2.0.6 - Information Disclosure - rules observed: 930130, 949110, 980170
- CVE-2022-2863 - WordPress WPvivid Backup <0.9.76 - Local File Inclusion - rules observed: 377360
- CVE-2024-10708 - System Dashboard < 2.8.15 - Admin+ Path Traversal - rules observed: 377360
- CVE-2020-29475 - nopCommerce Store 4.30 - ’name’ Stored Cross-Site Scripting - rules observed: 941100, 941120, 941160, 941390, 949110, 980170
- CVE-2021-24681 - Duplicate Page WordPress - Stored Cross-Site Scripting - rules observed: 377360
- CVE-2022-0535 - WordPress E2Pdf <1.16.45 - Cross-Site Scripting - rules observed: 377360
- CVE-2022-0873 - WordPress Gmedia Photo Gallery Plugin < 1.20.0 - Cross-Site Scripting - rules observed: 377360
- CVE-2022-1029 - Limit Login Attempts - Stored Cross-Site Scripting - rules observed: 377360
- CVE-2022-4260 - WordPress WP-Ban <1.69.1 - Stored Cross-Site Scripting - rules observed: 377360
- CVE-2023-2009 - Pretty Url <= 1.5.4 - Cross-Site Scripting - rules observed: 377360
- CVE-2023-2178 - Aajoda Testimonials < 2.2.2 - Cross-Site Scripting - rules observed: 377360, 941100, 941110, 941160, 941180, 941390, 949110, 980170
- CVE-2023-2224 - Seo By 10Web < 1.2.7 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-57514 - TP-Link Archer A20 v3 Router - Cross-site Scripting - rules observed: 930100, 930110, 949110, 980170
- CVE-2022-2546 - WordPress All-in-One WP Migration <=7.62 - Cross-Site Scripting - rules observed: 377360
- CVE-2024-13627 - OWL Carousel Slider - Cross-Site Scripting - rules observed: 377360
- CVE-2024-55550 - Mitel MiCollab - Arbitary File Read - rules observed: 930110, 949110, 980170
- CVE-2012-0782 - WordPress Core 3.3.1 - Multiple Vulnerabilities - rules observed: 930130, 949110, 980170
- CVE-2018-11784 - Apache Tomcat - Open Redirect - rules observed: 920440, 949110, 980170
- CVE-2020-5284 - Next.js <9.3.2 - Local File Inclusion - rules observed: 930100, 930110, 949110, 980170
- CVE-2021-37704 - phpfastcache - phpinfo Resource Exposure - rules observed: 930130, 949110, 980170
- CVE-2022-29495 - WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery - rules observed: 377360
- CVE-2023-23897 - Ozette Plugins - Cross-Site Request Forgery - rules observed: 377360
- CVE-2021-25075 - WordPress Duplicate Page or Post <1.5.1 - Cross-Site Scripting - rules observed: 377360, 941100, 941120, 941160, 941390, 949110, 980170
- CVE-2024-8673 - Z-Downloads < 1.11.7 - Cross-Site Scripting - rules observed: 377360
- CVE-2018-16341 - Nuxeo <10.3 - Remote Code Execution - rules observed: 933135, 941130, 949110, 980170
- CVE-2021-26292 - AfterLogic Aurora and WebMail Pro < 7.7.9 - Full Path Disclosure - rules observed: 911100, 949110, 980170
- CVE-2026-11111 - Research note for exploit techniques associated with CVE-2026-11111 - rules observed: 340016, 340162
- CVE-2026-48907 - Research note for exploit techniques associated with CVE-2026-48907 - rules observed: 383871, 333360