Atomicorp WAF Research Notes

Research Update - 2026-08-24

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-53545Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-55085Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-45272MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-62668Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-66794Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2025-55526n8n workflow collection Path Traversal Vulnerability344360 , 347009 , 390709
CVE-2026-48024Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager340007 , 344360 , 390709
CVE-2026-48162Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pa340007 , 344360 , 350591 , 390709
CVE-2026-49849xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution351000
CVE-2026-62674Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2017-20260Joomla! Component Price Alert 3.0.2 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20261Joomla! Component Bargain Product VM3 1.0 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20263Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via location340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20266Joomla SP Movie Database 1.3 SQL Injection via searchword340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20267Joomla! Component Calendar Planner 1.0.1 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20268Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20269Joomla! Component KissGallery 1.0.0 SQL Injection340145 , 380122
CVE-2017-20271Joomla StreetGuessr Game 1.1.8 SQL Injection via catid340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20272Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20273Joomla Event Registration Pro Calendar 4.1.3 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20274Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20275Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20276Joomla! Component SIMGenealogy 2.1.5 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20277Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20278Joomla JoomRecipe 1.0.3 SQL Injection via category parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20279Joomla Payage 2.05 SQL Injection via aid Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20280Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20281Joomla! Component Extra Search 2.2.8 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2017-20282Joomla! Component jCart for OpenCart 2.0 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25748Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25750Joomla J-MultipleHotelReservation 6.0.7 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25751Joomla J-ClassifiedsManager 3.0.5 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25752Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25756Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-44829Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename340007 , 344360 , 390709
CVE-2026-62675Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-62677Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUN340007 , 344360 , 390709
CVE-2026-61518ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-63722ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655
CVE-2026-64850Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655
CVE-2026-68899Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-53804OTRS Community Edition OS Command Injection via PGP Configuration340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-76205phpMyFAQ before 4.1.7 SQL Injection via Glossary340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76635baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-64851Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-68558Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446)337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-75933Jet Admin Stored XSS333140 , 333141 , 340095 , 342259
CVE-2026-77072n8n before 1.123.69 Stored XSS via Form Completion Page333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-22681OpenViking < 0.3.4 SSRF via /api/v1/resources337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-48105Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path340007 , 344360 , 390709
CVE-2026-76225ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV337109 , 337110 , 340162 , 340163 , 344360 , 390109 , 398021 , 398022
CVE-2026-63135YOURLS: Stored XSS in referrer statistics chart via crafted Referer header333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-64679Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation340007 , 344360 , 390709
CVE-2026-53549Termix: Server-Side Request Forgery via Proxy Connectivity Test337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-77775Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Validation337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398021 , 398022
CVE-2026-30819Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-15686Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-18274Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability340007 , 344360 , 390709
CVE-2026-18430HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason333140 , 333141 , 340147 , 340148 , 346755
CVE-2026-18756HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2019-25749Joomla J-CruisePortal 6.0.4 SQL Injection via cruises340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2019-25761Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-47735Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks340007 , 344360 , 390709 , 390719
CVE-2026-76210phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export340007 , 344360 , 347009 , 390709
CVE-2026-54134OctoPrint: File exfiltration possible via query parameters on upload endpoints340007 , 344360 , 347009 , 390709
CVE-2019-25760Joomla! Component Easy Shop 1.2.3 Local File Inclusion340007 , 344360 , 347009 , 390709
CVE-2026-59809SiYuan before v3.8.0 Secret Exfiltration via http_request URL337109 , 347009 , 390722
CVE-2026-73255Mongoose: Path traversal in SSI #include directives enables arbitrary file read340007 , 344360 , 347009 , 390709
CVE-2026-43980Malla: Stored XSS via Meshtastic node names in multiple frontend pages333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-728609router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unre337109 , 337110 , 344360 , 390719 , 398021 , 398022
CVE-2020-1106Microsoft Office SharePoint XSS Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2023-5758firefox mobile Cross-Site Scripting Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-55087Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (ope333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-49244SFTPGo: Path confinement bypass in public browsable share partial ZIP download340007 , 344360 , 347009 , 390709
CVE-2026-75628Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa344365
CVE-2026-76574code-projects Hospital Information System User Login UsersController.php login sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76760chenhg5 cc-connect webhook.go authenticate code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76761chenhg5 cc-connect Management API engine.go shellExecCommand os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76762code-projects Assessment Management welcome.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76764code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76795AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-76990code-projects Simple Inventory System delete.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76996SourceCodester Simple Online Food Ordering System view_order.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76998SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injection340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-77019CodeAstro Apartment Visitor Management System forgotpw.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-77020CodeAstro Apartment Visitor Management System password-recovery.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572
CVE-2026-78143code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78171itsourcecode Sales and Inventory System processlogin.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78197SourceCodester Simple Online Food Ordering System ajax.php save_user sql injection340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-78198SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-78199SourceCodester Simple Online Food Ordering System view_prod.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78201itsourcecode Payroll System admin_class.php login sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-53452Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPath340007 , 344360 , 390709
CVE-2026-54508TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolution337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-72846Lightdash Scheduled Delivery Webhook URLs Are Not Validated, Allowing Server-Side Request Forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-76239Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_address337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-76614OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore340007 , 344360 , 390709
CVE-2026-77067Omnivore Stored Server-Side Request Forgery via the setWebhook Mutation337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-40507OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259
CVE-2026-40508OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-55185Miniflux 2: Open Redirect Bypass344365
CVE-2026-76203CSS sanitizer bypass in Pentestify report themes allows forced outbound requests337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-53468Typemill has Stored HTML Attribute Injection in Metadata Fields333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-77648Glance Server-Side Request Forgery Vulnerability337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2025-10592itsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76576yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal340007 , 344360 , 347009 , 390709
CVE-2026-76785amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76991itsourcecode Hospital Management System viewappointmentapproved.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76997SourceCodester Simple Online Food Ordering System ajax.php save_category sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-77025itsourcecode Hospital Management System viewappointmentpending.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-77681CodeAstro Online Job Portal update-profile.php unrestricted upload351000
CVE-2026-78054SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78055SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78056sambitraj Student-Management-System Dashboard sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78057sambitraj Student-Management-System Management Mutation sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78059SourceCodester Stock Management System printOrder.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-78060SourceCodester Stock Management System getOrderReport.php cross site scripting333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-78112itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78166provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-78185itsourcecode Sales and Inventory System cust_edit.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78200itsourcecode Library Management System editbooks.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-76995SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted upload351000
CVE-2026-78140Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2026-78187Piwigo Public Authentication cross site scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148