Atomicorp WAF Research Notes

Research Update - 2026-08-25

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-51366Bottinelli Informatica Vedo Suite v.1.2.5 Arbitrary Code Execution Vulnerability340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2023-25826OpenTSDB <= 2.4.1 - Unauthenticated RCE via Gnuplot Injection340029 , 344363 , 390722
CVE-2024-31823ecommerce-codeigniter-bootstrap Arbitrary Code Execution Vulnerability344360
CVE-2025-14998Branda WordPress plugin - Privilege Escalation377360
CVE-2026-11387SMS Alert – SMS & OTP for WooCommerce - Privilege Escalation377360
CVE-2026-19598Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX Router377360
CVE-2026-71921DrayTek VigorSwitch Multiple Models Pre-Authentication OS Command Injection via setget.cgi340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-76070Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76071Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-73570zimbra collaboration suite Arbitrary Code Execution Vulnerability340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-76842Mercado Pago Node.js SDK through 3.4.0 Path Injection via Unencoded Identifiers in Payment Clients340007 , 344360 , 347009 , 390709
CVE-2026-79662Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass340162 , 340163 , 340165 , 344365
CVE-2026-34100Guardian Language-System SQL Injection via id Parameter in media.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34101Guardian Language-System SQL Injection via id Parameter in text_file.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34102Guardian Language-System SQL Injection via id Parameter in job_info_get.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34103Guardian Language-System SQL Injection via id Parameter in subtitles.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34104Guardian Language-System SQL Injection via name Parameter in designer.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-34105Guardian Language-System SQL Injection via id Parameter in translate_text.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-57863Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpoint340007 , 344360 , 390709
CVE-2026-72830Grav API Plugin before 1.0.13 RCE via ConfigController scope bypass340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76836AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Serialization Group Bypass340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-78416Authenticated RCE via condition.config JSON cleanse bypass340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-56703Adminer before 5.4.3 Remote Code Execution via SQLite VACUUM INTO340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390501 , 393655
CVE-2026-71906DrayTek VigorAP Multiple Models OS Command Injection via setLan340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71907DrayTek VigorAP Multiple Models OS Command Injection via setcamset340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71908DrayTek VigorAP Multiple Models OS Command Injection via mesh_start_speed_test340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71913DrayTek VigorAP Multiple Models OS Command Injection via upload_settings.cgi340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71915DrayTek VigorSwitch Multiple Models OS Command Injection via jsonstatus340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71918DrayTek VigorSwitch Multiple Models OS Command Injection via webBackupAction340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71919DrayTek VigorSwitch Multiple Models OS Command Injection via sysreboot340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-71923DrayTek VigorSwitch Multiple Models OS Command Injection via auth_set340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71924DrayTek VigorSwitch Multiple Models OS Command Injection via getVid340014 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71925DrayTek VigorSwitch Multiple Models OS Command Injection via getDetail340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71926DrayTek VigorSwitch Multiple Models OS Command Injection via setDevice340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71927DrayTek VigorSwitch Multiple Models OS Command Injection via rebDevice340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71928DrayTek VigorSwitch Multiple Models OS Command Injection via fdftDevice340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71929DrayTek VigorSwitch Multiple Models OS Command Injection via setDevProto340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71930DrayTek VigorSwitch Multiple Models OS Command Injection via setTime340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-71931DrayTek VigorSwitch Multiple Models OS Command Injection via tftp_upgrade340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-71943DrayTek VigorSwitch Multiple Models OS Command Injection via setDevNet340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-76844webpack-dev-middleware Path Traversal via Offset Slice on a Non-Slash-Terminated publicPath347009
CVE-2026-79659Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-34968Adminer before 5.4.3 Arbitrary File Deletion via SQLite Drop340007 , 344360 , 390709
CVE-2026-56702Adminer before 5.4.3 Unrestricted File Upload via AdminerFileUpload351000
CVE-2026-72695Grav before 2.0.16 Path Traversal via MediaUploadTrait deleteFile344360
CVE-2026-34964Adminer before 5.5.0 SSRF via PDO DSN Injection337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-71932DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile340007 , 344360 , 347009 , 390709
CVE-2026-78886liketrek TREK Public Journey Photo Proxy journey-public.controller.ts path traversal340007 , 344360 , 347009 , 390709
CVE-2026-78202itsourcecode Payroll System admin_class.php save_settings unrestricted upload351000
CVE-2026-78244itsourcecode Real Estate Management System search.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78245itsourcecode Online Pharmacy System User Registration register.php move_uploaded_file unrestricted upload351000
CVE-2026-78246itsourcecode Online Clinic Management System Admin Login login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78247SourceCodester Simple Online Food Ordering System ajax.php confirm_order sql injection340016 , 340017 , 340144 , 340156 , 340157 , 360147 , 360148 , 380122
CVE-2026-78248SourceCodester Simple Online Food Ordering System ajax.php save_settings sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341245 , 360147 , 360148 , 380122
CVE-2026-34959Adminer before 5.5.0 Open Redirect via X-Forwarded-Prefix340165 , 344365
CVE-2026-34967Adminer sql-log Plugin 5.3.0 through 5.4.2 Arbitrary File Write340007 , 344360 , 347009 , 390709
CVE-2026-76837Baserow before 2.3.0 Stored Cross-Site Scripting via Rich Text Mention Display Name333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-78864liketrek TREK Journey Entry Update journey.controller.t journeyService.updateEntry sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-71503Dolibarr < 24.0.0 Reflected XSS via Extra Fields Administration Template333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-79671Ech0 before 4.4.3 SSRF via DNS Resolution Bypass337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-78337Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG351000
CVE-2026-79670Ech0 before 4.4.3 Stored XSS via SVG Upload333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-16434Adminer before 5.5.1 X-Forwarded-Prefix Backslash Bypass340007 , 344360 , 347009 , 390709 , 390719
CVE-2026-66882Reflected XSS in AshAuthentication confirmation and magic link interaction forms333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-78656itsourcecode Sales and Inventory System cust_del.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-78435Faveo Helpdesk Logo SettingsController.php unlink path traversal340007 , 344360 , 347009