Atomicorp WAF Research Notes
Research Update - 2026-08-24
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-53545 | Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-55085 | Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-45272 | MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-62668 | Grav API Plugin: Webhook SSRF via Unrestricted cURL Protocols | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-66794 | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluster services via public route | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2025-55526 | n8n workflow collection Path Traversal Vulnerability | 344360 , 347009 , 390709 |
| CVE-2026-48024 | Wazuh: merged-file header path traversal in cluster sync allows arbitrary file write under WAZUH_PATH in Wazuh manager | 340007 , 344360 , 390709 |
| CVE-2026-48162 | Wazuh: cluster peer can read arbitrary master files and forge offline REST API administrator tokens via DAPI tmp_file pa | 340007 , 344360 , 350591 , 390709 |
| CVE-2026-49849 | xShop: Unrestricted File Upload in File Attachment Module in Admin panel leads to Arbitrary Code Execution | 351000 |
| CVE-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2017-20260 | Joomla! Component Price Alert 3.0.2 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20261 | Joomla! Component Bargain Product VM3 1.0 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20263 | Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via location | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20266 | Joomla SP Movie Database 1.3 SQL Injection via searchword | 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20267 | Joomla! Component Calendar Planner 1.0.1 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20268 | Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20269 | Joomla! Component KissGallery 1.0.0 SQL Injection | 340145 , 380122 |
| CVE-2017-20271 | Joomla StreetGuessr Game 1.1.8 SQL Injection via catid | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20272 | Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20273 | Joomla Event Registration Pro Calendar 4.1.3 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20274 | Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20275 | Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20276 | Joomla! Component SIMGenealogy 2.1.5 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20277 | Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20278 | Joomla JoomRecipe 1.0.3 SQL Injection via category parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20279 | Joomla Payage 2.05 SQL Injection via aid Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20280 | Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20281 | Joomla! Component Extra Search 2.2.8 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2017-20282 | Joomla! Component jCart for OpenCart 2.0 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25748 | Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25750 | Joomla J-MultipleHotelReservation 6.0.7 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25751 | Joomla J-ClassifiedsManager 3.0.5 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25752 | Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25756 | Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-44829 | Gotenberg: Path traversal in zip entry name via Windows-style separators in upload filename | 340007 , 344360 , 390709 |
| CVE-2026-62675 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-62677 | Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUN | 340007 , 344360 , 390709 |
| CVE-2026-61518 | ISPConfig Authenticated SQL Injection via Remote API primary_id Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-63722 | ICEcoder 8.1 Unauthenticated RCE via terminal-xhr.php | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 390904 , 393655 |
| CVE-2026-64850 | Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344365 , 344366 , 344370 , 393655 |
| CVE-2026-68899 | Wekan: File Upload MIME Type Validation Bypass — Stored XSS via Missing System Binary Fallback | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-53804 | OTRS Community Edition OS Command Injection via PGP Configuration | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655 |
| CVE-2026-76205 | phpMyFAQ before 4.1.7 SQL Injection via Glossary | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76635 | baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-64851 | Grav Shortcode Core Plugin: Stored XSS in shortcode-core attribute handlers | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-68558 | Wekan: SSRF filter bypass via DNS-resolving hostname in outgoing webhooks (incomplete fix of CVE-2026-53446) | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-75933 | Jet Admin Stored XSS | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-77072 | n8n before 1.123.69 Stored XSS via Form Completion Page | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-22681 | OpenViking < 0.3.4 SSRF via /api/v1/resources | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-48105 | Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path | 340007 , 344360 , 390709 |
| CVE-2026-76225 | ArcadeDB before 26.8.1 Server-Side Request Forgery via LOAD CSV | 337109 , 337110 , 340162 , 340163 , 344360 , 390109 , 398021 , 398022 |
| CVE-2026-63135 | YOURLS: Stored XSS in referrer statistics chart via crafted Referer header | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-64679 | Atlantis: Path Traversal in Atlantis Workspace Handling Allows Out-of-Bounds Directory Deletion/Creation | 340007 , 344360 , 390709 |
| CVE-2026-53549 | Termix: Server-Side Request Forgery via Proxy Connectivity Test | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-77775 | Headroom Proxy Sends Upstream Requests to a Client-Supplied Base URL Without Address Validation | 337109 , 337110 , 340165 , 344360 , 347009 , 390719 , 390722 , 398021 , 398022 |
| CVE-2026-30819 | Combodo iTop: Reflected XSS in /pages/ajax.render.php dashboard_id parameter | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-15686 | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability | 340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-18274 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability | 340007 , 344360 , 390709 |
| CVE-2026-18430 | HumHub 1.18.4 - Stored XSS in comment-deletion notifications through unescaped administrator reason | 333140 , 333141 , 340147 , 340148 , 346755 |
| CVE-2026-18756 | HumHub Community Edition 1.18.4-pl1 - Reflected XSS in Space membership request button rendering | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2019-25749 | Joomla J-CruisePortal 6.0.4 SQL Injection via cruises | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2019-25761 | Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-47735 | Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks | 340007 , 344360 , 390709 , 390719 |
| CVE-2026-76210 | phpMyFAQ before v4.1.6 Local File Disclosure via PDF Export | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-54134 | OctoPrint: File exfiltration possible via query parameters on upload endpoints | 340007 , 344360 , 347009 , 390709 |
| CVE-2019-25760 | Joomla! Component Easy Shop 1.2.3 Local File Inclusion | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-59809 | SiYuan before v3.8.0 Secret Exfiltration via http_request URL | 337109 , 347009 , 390722 |
| CVE-2026-73255 | Mongoose: Path traversal in SSI #include directives enables arbitrary file read | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-43980 | Malla: Stored XSS via Meshtastic node names in multiple frontend pages | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-72860 | 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unre | 337109 , 337110 , 344360 , 390719 , 398021 , 398022 |
| CVE-2020-1106 | Microsoft Office SharePoint XSS Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2023-5758 | firefox mobile Cross-Site Scripting Vulnerability | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-55087 | Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (ope | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-49244 | SFTPGo: Path confinement bypass in public browsable share partial ZIP download | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-75628 | Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_pa | 344365 |
| CVE-2026-76574 | code-projects Hospital Information System User Login UsersController.php login sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76760 | chenhg5 cc-connect webhook.go authenticate code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-76761 | chenhg5 cc-connect Management API engine.go shellExecCommand os command injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-76762 | code-projects Assessment Management welcome.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76764 | code-projects Employee Management System Admin Login Endpoint aprocess.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76795 | AeternaLabsHQ PullMD REST API Endpoint api server-side request forgery | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-76990 | code-projects Simple Inventory System delete.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76996 | SourceCodester Simple Online Food Ordering System view_order.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76998 | SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122 |
| CVE-2026-77019 | CodeAstro Apartment Visitor Management System forgotpw.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-77020 | CodeAstro Apartment Visitor Management System password-recovery.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 , 390572 |
| CVE-2026-78143 | code-projects Barangay Resident Profiling Management System Resident Search Functionality residents.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78171 | itsourcecode Sales and Inventory System processlogin.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78197 | SourceCodester Simple Online Food Ordering System ajax.php save_user sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122 |
| CVE-2026-78198 | SourceCodester Simple Online Food Ordering System ajax.php add_to_cart sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-78199 | SourceCodester Simple Online Food Ordering System view_prod.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78201 | itsourcecode Payroll System admin_class.php login sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-53452 | Ground Station: Unauthenticated out-of-containment file read via sigmfplayback recordingPath | 340007 , 344360 , 390709 |
| CVE-2026-54508 | TREK: Blind SSRF via unvalidated redirect-following in Google/Naver list import and Maps URL resolution | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-72846 | Lightdash Scheduled Delivery Webhook URLs Are Not Validated, Allowing Server-Side Request Forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-76239 | Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_address | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-76614 | OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restore | 340007 , 344360 , 390709 |
| CVE-2026-77067 | Omnivore Stored Server-Side Request Forgery via the setWebhook Mutation | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-40507 | OpenEMR < 8.3.0 Reflected XSS via templateHtml Parameter in Patient Portal | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 341099 , 341266 , 342259 |
| CVE-2026-40508 | OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-55185 | Miniflux 2: Open Redirect Bypass | 344365 |
| CVE-2026-76203 | CSS sanitizer bypass in Pentestify report themes allows forced outbound requests | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-53468 | Typemill has Stored HTML Attribute Injection in Metadata Fields | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-77648 | Glance Server-Side Request Forgery Vulnerability | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2025-10592 | itsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76576 | yangzongzhuan RuoYi-Vue Common Download Endpoint CommonController.java resourceDownload path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-76785 | amirsanni Mini-Inventory-and-Sales-Management-System Transaction.php getAll sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76991 | itsourcecode Hospital Management System viewappointmentapproved.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76997 | SourceCodester Simple Online Food Ordering System ajax.php save_category sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-77025 | itsourcecode Hospital Management System viewappointmentpending.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-77681 | CodeAstro Online Job Portal update-profile.php unrestricted upload | 351000 |
| CVE-2026-78054 | SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78055 | SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78056 | sambitraj Student-Management-System Dashboard sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78057 | sambitraj Student-Management-System Management Mutation sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78059 | SourceCodester Stock Management System printOrder.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78060 | SourceCodester Stock Management System getOrderReport.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-78112 | itsourcecode Hospital Management System Project in PHP viewservicetype.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78166 | provectus kafka-ui Groovy Code MessagesController.java executeSmartFilterTest code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-78185 | itsourcecode Sales and Inventory System cust_edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-78200 | itsourcecode Library Management System editbooks.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-76995 | SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted upload | 351000 |
| CVE-2026-78140 | Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-78187 | Piwigo Public Authentication cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |