Atomicorp WAF Research Notes
Research Update - 2026-08-07
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2025-32432 | CraftCMS - Remote Code Execution | 344365 |
| CVE-2026-47668 | DbGate - Remote Code Execution via Anonymous JWT | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 360151 , 380026 |
| CVE-2026-53576 | Kestra <= 1.3.20 - Remote Code Execution | 391213 |
| CVE-2024-46986 | Camaleon CMS < 2.8.1 Arbitrary File Write to RCE | 392647 |
| CVE-2025-23211 | Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCE | 330791 , 340152 |
| CVE-2026-34156 | NocoBase - VM Sandbox Escape to Remote Code Execution | 344370 , 345240 , 360151 |
| CVE-2020-24881 | OsTicket < 1.14.3 - Server Side Request Forgery | 340147 , 340148 |
| CVE-2020-26935 | phpMyAdmin < 5.0.3 - SQL Injection | 340016 , 340017 , 340157 , 341245 , 360147 , 360148 |
| CVE-2021-24139 | 10Web Photo Gallery < 1.5.55 - SQL Injection | 341245 , 380026 , 380122 |
| CVE-2021-26599 | ImpressCMS < 1.4.3 - SQL Injection | 341245 , 380026 , 380122 |
| CVE-2022-24086 | Adobe Commerce (Magento) - Remote Code Execution | 344360 , 344370 |
| CVE-2023-26035 | ZoneMinder Snapshots - Command Injection | 344364 , 344366 |
| CVE-2023-2734 | MStore API <= 3.9.1 - Authentication Bypass | 330791 , 340152 |
| CVE-2024-30502 | WP Travel Engine <= 5.7.9 - SQL Injection | 330791 , 340016 , 340017 , 340152 , 340157 , 360147 , 360148 , 380026 , 380122 |
| CVE-2024-32238 | H3C ER8300G2-X - Password Disclosure | 390716 |
| CVE-2024-3408 | D-Tale 3.10.0 - 3.15.1 - Authentication Bypass & Remote Code Execution | 340087 , 340095 |
| CVE-2024-43144 | Cost Calculator Builder <= 3.2.15 - SQL Injection | 380122 |
| CVE-2024-43917 | WordPress TI WooCommerce Wishlist Plugin <= 2.8.2 - SQL Injection | 380026 , 380122 |
| CVE-2024-50623 | Cleo Harmony < 5.8.0.21 - Arbitary File Read | 344365 |
| CVE-2025-56819 | Datart v1.0.0-rc.3 - Remote Code Execution | 337209 , 337211 , 340095 |
| CVE-2025-59287 | Windows Server Update Service - Insecure Deserialization | 392647 |
| CVE-2026-0926 | Prodigy Commerce <= 3.3.0 - Local File Inclusion | 344360 |
| CVE-2026-44262 | Scramble Laravel - Remote Code Execution | 341245 , 380026 , 380122 |
| CVE-2026-47670 | DbGate - Remote Code Execution via Dynamic Import Bypass | 340014 , 340023 , 340029 , 340149 , 340162 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 346755 , 380026 , 393655 |
| CVE-2025-2611 | ICTBroadcast - Command Injection | 344361 , 393655 |
| CVE-2026-42647 | JoomSport <= 5.7.7 - SQL Injection | 341245 , 344366 , 380122 |
| CVE-2026-46725 | TYPO3 ceselector Extension - Insecure Deserialization | 360153 |
| CVE-2022-4223 | pgAdmin < 6.17 - Unauthenticated Remote Code Execution | 393655 |
| CVE-2024-1751 | Tutor LMS <= 2.1.10 - SQL Injection | 380122 |
| CVE-2024-28253 | OpenMetaData - SpEL Injection in PUT /api/v1/policies | 337209 , 337210 , 337211 , 340095 |
| CVE-2026-22200 | osTicket - Arbitrary File Read | 340147 , 340148 |
| CVE-2024-24809 | Traccar - Unrestricted File Upload | 330791 , 340152 , 391213 |
| CVE-2024-29889 | GLPI 10.0.10-10.0.14 - SQL Injection | 341245 |
| CVE-2024-43425 | Moodle - Remote Code Execution | 340095 , 360152 |
| CVE-2019-9757 | LabKey Server 19.1.0 - XML External Entity (XXE) | 340029 , 341256 , 342259 , 344360 , 344372 , 380018 |
| CVE-2023-40211 | Post Grid <= 2.2.50 - Information Exposure via REST API | 330791 , 340152 |
| CVE-2024-11728 | KiviCare Clinic & Patient Management System (EHR) <= 3.6.4 - SQL Injection | 340016 , 340017 , 340156 , 380122 |
| CVE-2025-2539 | File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read | 340748 , 344360 , 347006 , 390709 |
| CVE-2024-11320 | Pandora v7.0NG.777.3 - Remote Code Execution | 344363 |
| CVE-2024-55890 | D-Tale <= 3.16.0 - Pre-Auth RCE via Pandas Query Injection | 344370 |
| CVE-2026-31807 | SiYuan <= v3.5.9 - SVG Animate Element XSS | 300013 |
| CVE-2013-2621 | Telaen => v1.3.1 - Open Redirect | 320007 |
| CVE-2016-15041 | MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scripting | 333141 , 340149 , 346755 |
| CVE-2018-7192 | osTicket < 1.10.2 - Cross-Site Scripting | 344361 , 344364 , 346755 , 347198 |
| CVE-2018-7193 | osTicket < 1.10.2 - Cross-Site Scripting | 340147 , 341266 , 342259 |
| CVE-2018-7196 | osTicket < 1.10.2 - Cross-Site Scripting | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2019-11507 | Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected) | 333141 , 341256 , 342259 , 346755 , 347198 , 350148 , 390722 |
| CVE-2022-34305 | Apache Tomcat Examples Web Application - Cross-Site Scripting | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 |
| CVE-2023-6000 | WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSS | 346755 , 350148 |
| CVE-2026-0594 | WordPress List Site Contributors < 1.1.8 - Reflected XSS | 333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148 |
| CVE-2026-17505 | WordPress TranslatePress < 3.2.6 - Cross-Site Scripting | 333141 , 341256 , 346755 , 347198 , 350148 |
| CVE-2023-1317 | osTicket < v1.16.6 - Cross-Site Scripting | 340099 , 341099 , 347198 |
| CVE-2025-62780 | ChangeDetection.io <= v0.50.33 - Stored XSS via Watch API | 346755 , 350148 |
| CVE-2016-2388 | SAP NetWeaver J2EE Engine 7.40 - SQL Injection | 340016 , 340156 , 341245 , 380026 , 390704 |
| CVE-2025-51990 | XWiki – Stored Cross-Site Scripting (XSS) | 342259 |