Atomicorp WAF Research Notes
Research Update - 2026-08-31
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2017-8225 | GoAhead Camera - Credential Disclosure | 390716 |
| CVE-2026-42596 | Gotenberg < 8.31.0 - Server-Side Request Forgery | 344362 , 398004 |
| CVE-2026-77956 | EEx template evaluation of prompt content in AshAi enables remote code execution | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2026-82638 | jina-ai reader Server-Side Request Forgery via disabled private-address guard | 344360 , 347009 , 390719 , 390722 , 398001 , 398021 |
| CVE-2026-82655 | Admidio before 5.0.12 SQL Injection via relation_type_list | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-77850 | Stored XSS in AshAdmin relationship typeahead via unescaped label_field content | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-82673 | Path traversal in AshAdmin file uploads via unsanitized client filename | 340007 , 344360 , 390709 |
| CVE-2026-9133 | Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File Read | 344360 |
| CVE-2026-82650 | SiYuan before v3.8.1 Path Traversal via /api/template/render | 340007 , 344360 , 390709 |
| CVE-2026-82598 | SeaCMS Template search.php parseIf code injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-82600 | SeaCMS zyapi.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82610 | itsourcecode Online Medicine Delivery System Login login.php employeeAuthentication sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82611 | itsourcecode Online Medicine Delivery System Customer Login login.php cusAuthentication sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82612 | itsourcecode Online Medicine Delivery System Product Detail index.php loadResultList sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82613 | itsourcecode Online Medicine Delivery System Product Search index.php loadResultList sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82614 | itsourcecode Online Medicine Delivery System Product Category Filter index.php loadResultList sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82615 | itsourcecode Online Medicine Delivery System Password Recovery passwordrecover.php find_phone sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82451 | Formwork through 2.3.14 Stored XSS via Referer Header | 333140 , 333141 , 340003 , 340087 , 340095 , 340099 , 340147 , 340158 , 341099 , 341266 , 342259 |
| CVE-2026-82646 | WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-0743 | WP Content Permission <= 1.2 - Cross-Site Scripting | 346755 , 377360 , 390585 |
| CVE-2026-82421 | itsourcecode Sales and Inventory System emp_edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82422 | itsourcecode Sales and Inventory System emp_del.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82424 | PHPGurukul Student Information System student_edit1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82484 | itsourcecode Sales and Inventory System emp_searchfrm.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82485 | itsourcecode Sales and Inventory System pro_edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82540 | itsourcecode Sales and Inventory System cust_searchfrm.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82541 | itsourcecode Sales and Inventory System sup_edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82545 | itsourcecode Sales and Inventory System sup_searchfrm.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82599 | SeaCMS Avatar Upload member.php unlink path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-82601 | SeaCMS err.php cross site scripting | 333140 , 333141 , 340087 , 340099 , 340147 , 341099 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-82603 | SeaCMS Comment Cache member.php del_pl path traversal | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-82609 | itsourcecode Sales and Inventory System inv_edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-82656 | Admidio before 5.0.12 Path Traversal via Photo ZIP Download | 340007 , 344360 , 390709 |
| CVE-2026-82483 | coppermine-gallery Coppermine Photo Gallery Hidden Album Update Endpoint db_input.php cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-82488 | Beetel 450TC3 User Management cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |