Atomicorp WAF Research Notes

Research Update - 2026-08-07

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2025-32432CraftCMS - Remote Code Execution344365
CVE-2026-47668DbGate - Remote Code Execution via Anonymous JWT340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 360151 , 380026
CVE-2026-53576Kestra <= 1.3.20 - Remote Code Execution391213
CVE-2024-46986Camaleon CMS < 2.8.1 Arbitrary File Write to RCE392647
CVE-2025-23211Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCE330791 , 340152
CVE-2026-34156NocoBase - VM Sandbox Escape to Remote Code Execution344370 , 345240 , 360151
CVE-2020-24881OsTicket < 1.14.3 - Server Side Request Forgery340147 , 340148
CVE-2020-26935phpMyAdmin < 5.0.3 - SQL Injection340016 , 340017 , 340157 , 341245 , 360147 , 360148
CVE-2021-2413910Web Photo Gallery < 1.5.55 - SQL Injection341245 , 380026 , 380122
CVE-2021-26599ImpressCMS < 1.4.3 - SQL Injection341245 , 380026 , 380122
CVE-2022-24086Adobe Commerce (Magento) - Remote Code Execution344360 , 344370
CVE-2023-26035ZoneMinder Snapshots - Command Injection344364 , 344366
CVE-2023-2734MStore API <= 3.9.1 - Authentication Bypass330791 , 340152
CVE-2024-30502WP Travel Engine <= 5.7.9 - SQL Injection330791 , 340016 , 340017 , 340152 , 340157 , 360147 , 360148 , 380026 , 380122
CVE-2024-32238H3C ER8300G2-X - Password Disclosure390716
CVE-2024-3408D-Tale 3.10.0 - 3.15.1 - Authentication Bypass & Remote Code Execution340087 , 340095
CVE-2024-43144Cost Calculator Builder <= 3.2.15 - SQL Injection380122
CVE-2024-43917WordPress TI WooCommerce Wishlist Plugin <= 2.8.2 - SQL Injection380026 , 380122
CVE-2024-50623Cleo Harmony < 5.8.0.21 - Arbitary File Read344365
CVE-2025-56819Datart v1.0.0-rc.3 - Remote Code Execution337209 , 337211 , 340095
CVE-2025-59287Windows Server Update Service - Insecure Deserialization392647
CVE-2026-0926Prodigy Commerce <= 3.3.0 - Local File Inclusion344360
CVE-2026-44262Scramble Laravel - Remote Code Execution341245 , 380026 , 380122
CVE-2026-47670DbGate - Remote Code Execution via Dynamic Import Bypass340014 , 340023 , 340029 , 340149 , 340162 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 345240 , 346755 , 380026 , 393655
CVE-2025-2611ICTBroadcast - Command Injection344361 , 393655
CVE-2026-42647JoomSport <= 5.7.7 - SQL Injection341245 , 344366 , 380122
CVE-2026-46725TYPO3 ceselector Extension - Insecure Deserialization360153
CVE-2022-4223pgAdmin < 6.17 - Unauthenticated Remote Code Execution393655
CVE-2024-1751Tutor LMS <= 2.1.10 - SQL Injection380122
CVE-2024-28253OpenMetaData - SpEL Injection in PUT /api/v1/policies337209 , 337210 , 337211 , 340095
CVE-2026-22200osTicket - Arbitrary File Read340147 , 340148
CVE-2024-24809Traccar - Unrestricted File Upload330791 , 340152 , 391213
CVE-2024-29889GLPI 10.0.10-10.0.14 - SQL Injection341245
CVE-2024-43425Moodle - Remote Code Execution340095 , 360152
CVE-2019-9757LabKey Server 19.1.0 - XML External Entity (XXE)340029 , 341256 , 342259 , 344360 , 344372 , 380018
CVE-2023-40211Post Grid <= 2.2.50 - Information Exposure via REST API330791 , 340152
CVE-2024-11728KiviCare Clinic & Patient Management System (EHR) <= 3.6.4 - SQL Injection340016 , 340017 , 340156 , 380122
CVE-2025-2539File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read340748 , 344360 , 347006 , 390709
CVE-2024-11320Pandora v7.0NG.777.3 - Remote Code Execution344363
CVE-2024-55890D-Tale <= 3.16.0 - Pre-Auth RCE via Pandas Query Injection344370
CVE-2026-31807SiYuan <= v3.5.9 - SVG Animate Element XSS300013
CVE-2013-2621Telaen => v1.3.1 - Open Redirect320007
CVE-2016-15041MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scripting333141 , 340149 , 346755
CVE-2018-7192osTicket < 1.10.2 - Cross-Site Scripting344361 , 344364 , 346755 , 347198
CVE-2018-7193osTicket < 1.10.2 - Cross-Site Scripting340147 , 341266 , 342259
CVE-2018-7196osTicket < 1.10.2 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-11507Pulse Secure Pulse Connect Secure - Cross-Site Scripting (Reflected)333141 , 341256 , 342259 , 346755 , 347198 , 350148 , 390722
CVE-2022-34305Apache Tomcat Examples Web Application - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2023-6000WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSS346755 , 350148
CVE-2026-0594WordPress List Site Contributors < 1.1.8 - Reflected XSS333141 , 341256 , 342259 , 346755 , 347198 , 350147 , 350148
CVE-2026-17505WordPress TranslatePress < 3.2.6 - Cross-Site Scripting333141 , 341256 , 346755 , 347198 , 350148
CVE-2023-1317osTicket < v1.16.6 - Cross-Site Scripting340099 , 341099 , 347198
CVE-2025-62780ChangeDetection.io <= v0.50.33 - Stored XSS via Watch API346755 , 350148
CVE-2016-2388SAP NetWeaver J2EE Engine 7.40 - SQL Injection340016 , 340156 , 341245 , 380026 , 390704
CVE-2025-51990XWiki – Stored Cross-Site Scripting (XSS)342259