Atomicorp WAF Research Notes
Research Update - 2026-09-06
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2022-22947 | Spring Cloud Gateway Code Injection | 344370 , 393655 |
| CVE-2024-46506 | NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution | 392301 , 392648 |
| CVE-2026-72876 | Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.* | 340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2015-7501 | Red Hat JBoss - Insecure Deserialization | 344380 |
| CVE-2018-1217 | Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control | 391213 |
| CVE-2018-12463 | Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection | 330791 , 340152 |
| CVE-2018-6530 | D-Link - Unauthenticated Remote Code Execution | 330791 , 340152 , 344363 |
| CVE-2018-7600 | Drupal - Remote Code Execution | 330791 , 340152 |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution | 391213 |
| CVE-2019-17506 | D-Link DIR-868L/817LW - Information Disclosure | 330791 , 340152 |
| CVE-2019-7194 | QNAP Photo Station < 6.0.3 - Remote Code Execution | 340128 , 380018 , 380026 , 390801 |
| CVE-2019-7238 | Sonatype Nexus Repository Manager <3.15.0 - Remote Code Execution | 344360 , 344363 , 344370 |
| CVE-2019-9670 | Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection | 344372 |
| CVE-2020-11975 | Apache Unomi - Remote Code Execution | 337210 |
| CVE-2020-15505 | MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Execution | 391213 |
| CVE-2021-21978 | VMware View Planner <4.6 SP1- Remote Code Execution | 330791 , 340007 , 340152 |
| CVE-2021-3378 | FortiLogger 4.4.2.2 - Arbitrary File Upload | 330791 , 340152 |
| CVE-2022-31181 | PrestaShop - SQL Injection to Eval Injection | 340157 , 340159 , 341245 , 344362 , 360147 , 360148 , 390704 |
| CVE-2022-3980 | Sophos Mobile managed on-premises - XML External Entity Injection | 344372 |
| CVE-2023-20887 | VMware VRealize Network Insight - Remote Code Execution | 391213 |
| CVE-2023-2648 | Weaver E-Office 9.5 - Remote Code Execution | 330791 , 340152 |
| CVE-2023-4450 | JeecgBoot JimuReport - Template injection | 340014 , 344370 , 393655 |
| CVE-2023-47248 | PyArrow Flight RPC - Remote Code Execution | 391213 |
| CVE-2024-0799 | Arcserve Unified Data Protection - Authentication Bypass | 391213 |
| CVE-2024-27348 | Apache HugeGraph-Server - Remote Command Execution | 380026 |
| CVE-2024-43965 | SendGrid for WordPress <= 1.4 - SQL Injection | 380122 |
| CVE-2024-55956 | Cleo Harmony < 5.8.0.24 - File Upload Vulnerability | 391213 |
| CVE-2024-7314 | AJ-Report < 1.4.1 - Remote Code Execution | 337209 , 337211 , 380026 |
| CVE-2024-8353 | GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection | 340014 , 344370 |
| CVE-2025-2776 | SysAid On-Prem <= 23.3.40 - XML External Entity | 330791 , 340152 , 344372 |
| CVE-2025-2777 | SysAid On-Prem <= 23.3.40 - XML External Entity | 330791 , 340152 , 344372 |
| CVE-2025-54123 | Hoverfly <= 1.11.3 - Remote Code Execution | 344360 |
| CVE-2025-58360 | GeoServer - XML External Entity Injection | 391213 |
| CVE-2025-61882 | Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Execution | 391213 |
| CVE-2025-66516 | Apache Tika - XML External Entity Injection | 391213 |
| CVE-2026-0770 | Langflow < 1.3.0 - Remote Code Execution via validate_code() exec() | 344360 , 344370 |
| CVE-2026-39394 | CI4MS has an .env CRLF Injection via Unvalidated host Parameter in Install Controller | 340007 , 344360 , 347009 |
| CVE-2026-25512 | Group-Office < 26.0.5 - Remote Code Execution | 344363 |
| CVE-2026-66398 | phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-77086 | SiYuan before v3.7.4 Path Traversal via packageName | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-86123 | SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-66396 | SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-86189 | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php | 340007 , 344360 , 390709 |
| CVE-2024-9465 | Palo Alto Expedition - SQL Injection | 340016 , 341245 , 380026 , 380122 |
| CVE-2026-27971 | Qwik - Unauthenticated RCE via server$ Deserialization | 391213 |
| CVE-2026-86119 | Webstudio through 0.296.0 SSRF via /cgi proxy routes | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2021-21351 | XStream <1.4.16 - Remote Code Execution | 344380 |
| CVE-2022-31678 | VMWare Cloud Foundation NSX-V - XML External Entity (XXE) | 344372 |
| CVE-2024-4180 | The Events Calendar < 6.4.0.1 - Cross-site Scripting | 346755 |
| CVE-2026-41042 | Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution | 344370 |
| CVE-2025-48703 | CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution | 330791 , 340152 |
| CVE-2019-25745 | WordPress Plugin Google Review Slider 6.1 SQL Injection via tid | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2021-25646 | Apache Druid - Remote Code Execution | 337209 , 337210 , 337211 , 340095 , 344360 , 344361 , 344370 , 380026 |
| CVE-2025-11307 | WP Google Maps < 9.0.48 - Cross-Site Scripting | 346755 |
| CVE-2026-40466 | Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypass | 330925 , 340162 , 340163 |
| CVE-2026-5027 | Langflow <= 1.8.4 - Path Traversal to RCE via File Upload | 300008 |
| CVE-2024-50334 | Scoold < 1.64.0 - Authentication Bypass | 391213 |
| CVE-2026-39352 | Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversal | 340007 , 340029 , 344360 , 344370 , 390709 |
| CVE-2026-67281 | Unauthenticated file read in Mikrotik RouterOS | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-70492 | Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages | 333140 , 333141 , 340147 , 340148 , 341256 , 346755 |
| CVE-2026-75574 | Grav before 4.2.2 Remote Code Execution via Email Twig | 340014 , 344361 , 344363 , 344364 , 344366 , 344370 |
| CVE-2025-64328 | FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command Injection | 344364 |
| CVE-2026-34605 | SiYuan Note - Cross-Site Scripting | 300013 |
| CVE-2026-84196 | Kyverno before 1.18.0 Server-Side Request Forgery via apiCall | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2025-6204 | DELMIA Apriso - Command Injection | 340095 , 341245 , 344361 , 344365 , 344366 , 347019 , 390724 |
| CVE-2011-3600 | Apache OFBiz - XML External Entity Injection | 344372 |
| CVE-2017-17762 | Episerver 7 - Blind XML External Entity Injection | 344372 |
| CVE-2019-11253 | Kubernetes API Server - YAML Parsing DoS (Billion Laughs) | 391213 |
| CVE-2019-13608 | Citrix StoreFront Server - XML External Entity | 344372 , 391213 |
| CVE-2019-8086 | Adobe Experience Manager - XML External Entity Injection | 330925 |
| CVE-2019-9621 | Zimbra Collaboration Suite - SSRF | 344372 |
| CVE-2020-11991 | Apache Cocoon 2.1.12 - XML Injection | 344372 |
| CVE-2022-2414 | FreeIPA - XML Entity Injection | 344372 |
| CVE-2024-38653 | Ivanti Avalanche SmartDeviceServer - XML External Entity | 330791 , 340152 |
| CVE-2025-2221 | WordPress WPCOM Member <= 1.7.6 - SQL Injection | 340016 , 380122 |
| CVE-2025-2775 | SysAid On-Prem <= 23.3.40 - XML External Entity | 330791 , 340152 , 344372 |
| CVE-2026-50151 | oras-go: credential forwarding via unvalidated Location header in blob upload | 390719 |
| CVE-2023-42344 | OpenCMS - XML external entity (XXE) | 330791 , 340152 , 344372 |
| CVE-2019-2616 | Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection | 330791 , 340152 |
| CVE-2023-46818 | ISPConfig - PHP Code Injection | 340095 |
| CVE-2024-38288 | TurboMeeting - Post-Authentication Command Injection | 344363 , 344370 |
| CVE-2024-8625 | WordPress TS Poll < 2.4.0 - SQL Injection | 380122 |
| CVE-2026-28409 | WeGIA <= 3.6.4 - Remote Code Execution | 344363 , 390700 , 393655 |
| CVE-2024-13352 | Legull WordPress - Cross-Site Scripting | 341266 , 346755 |
| CVE-2024-13625 | Tube Video Ads Lite - Reflected XSS | 341266 |
| CVE-2024-5082 | Nexus Repository 2 - Remote Code Execution | 330791 , 340152 |
| CVE-2026-82246 | Budibase Server before 3.41.3 SSRF via Query Import | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-79781 | rclone serve s3 Path Traversal via dot-dot object keys | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-82233 | SiYuan before v3.8.1 Path Traversal via asset.upload | 340007 , 344360 , 390709 |
| CVE-2026-86188 | AVideo YPTSocket Plugin Unauthenticated Cross-Site Scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-66472 | XWiki DeleteApplication - Cross-Site Scripting | 346755 |
| CVE-2026-54020 | Open WebUI: DNS Rebinding SSRF Bypass | 337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-72814 | actix-web before 0.6.10 Information Disclosure via Files | 340007 , 344360 , 347009 , 390709 |
| CVE-2016-10976 | Safe Editor Plugin < 1.2 - CSS/JS-injection | 346755 |
| CVE-2018-10141 | Palo Alto Networks PAN-OS GlobalProtect <8.1.4 - Cross-Site Scripting | 346755 |
| CVE-2018-11133 | Quest KACE SMA /common/run_cross_report.php 'fmt' XSS | 346755 |
| CVE-2019-14750 | osTicket < 1.12.1 - Cross-Site Scripting | 346755 |
| CVE-2019-17231 | WordPress OneTone theme <= 3.0.6 – Unauthenticated Stored XSS | 346755 |
| CVE-2019-9955 | Zyxel - Cross-Site Scripting | 346755 |
| CVE-2020-14408 | Agentejo Cockpit 0.10.2 - Cross-Site Scripting | 346755 |
| CVE-2020-15895 | D-Link DIR-816L 2.x - Cross-Site Scripting | 346755 |
| CVE-2020-23814 | XXL-JOB v2.2.0 — Stored Cross Site Scripting | 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 |
| CVE-2020-9036 | Jeedom <=4.0.38 - Cross-Site Scripting | 346755 |
| CVE-2021-22122 | FortiWeb - Cross Site Scripting | 346755 |
| CVE-2021-24351 | WordPress The Plus Addons for Elementor <4.1.12 - Cross-Site Scripting | 346755 |
| CVE-2021-24878 | SupportCandy < 2.2.7 - Reflected Cross-Site Scripting | 346755 |
| CVE-2021-26812 | Moodle Jitsi Meet 2.7-2.8.3 - Cross-Site Scripting | 346755 |
| CVE-2021-27909 | Mautic <3.3.4 - Cross-Site Scripting | 346755 |
| CVE-2021-30151 | Sidekiq <=6.2.0 - Cross-Site Scripting | 346755 |
| CVE-2021-33829 | Drupal 7 CKEditor XSS | 333141 |
| CVE-2021-40968 | Spotweb <= 1.5.1 - Cross Site Scripting | 346755 |
| CVE-2021-40969 | Spotweb <= 1.5.1 - Cross Site Scripting (Reflected) | 346755 |
| CVE-2021-40970 | Spotweb <= 1.5.1 - Cross Site Scripting | 346755 |
| CVE-2021-40971 | Spotweb <= 1.5.1 - Cross Site Scripting | 346755 |
| CVE-2021-40972 | Spotweb <= 1.5.1 - Cross Site Scripting | 346755 |
| CVE-2021-40973 | Spotweb <= 1.5.1 - Cross Site Scripting | 346755 |
| CVE-2021-41174 | Grafana 8.0.0 <= v.8.2.2 - Angularjs Rendering Cross-Site Scripting | 346755 |
| CVE-2021-42063 | SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scripting | 346755 |
| CVE-2021-42566 | myfactory FMS - Cross-Site Scripting | 346755 |
| CVE-2022-1597 | WordPress WPQA <5.4 - Cross-Site Scripting | 346755 |
| CVE-2022-1916 | WordPress Active Products Tables for WooCommerce <1.0.5 - Cross-Site Scripting | 346755 |
| CVE-2022-2627 | WordPress Newspaper < 12 - Cross-Site Scripting | 346755 |
| CVE-2022-29548 | WSO2 - Cross-Site Scripting | 346755 |
| CVE-2022-45365 | Stock Ticker <= 3.23.2 - Cross-Site-Scripting | 346755 |
| CVE-2023-29506 | XWiki >= 13.10.8 - Cross-Site Scripting | 346755 |
| CVE-2023-40208 | Stock Ticker <= 3.23.2 - Cross-Site Scripting | 346755 |
| CVE-2023-44813 | mooSocial v.3.1.8 - Cross-Site Scripting | 346755 |
| CVE-2024-12724 | WP DeskLite - Reflected XSS | 340148 , 341266 , 346755 |
| CVE-2024-13222 | WordPress User Messages <= 1.2.4 - Reflected XSS | 341266 , 346755 , 390585 |
| CVE-2024-13328 | Giga Messenger WordPress - Cross-Site Scripting | 341266 , 346755 |
| CVE-2024-28623 | RiteCMS 3.0.0 - Cross-site Scripting | 346755 , 380026 |
| CVE-2024-35627 | TileServer API - Cross Site Scripting | 346755 |
| CVE-2024-42852 | AcuToWeb server/10.5.0.7577c8b - Cross-Site Scripting | 346755 |
| CVE-2025-51501 | Microweber CMS2.0 - Cross-Site Scripting | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2025-51502 | Microweber CMS 2.0 - Reflected XSS in Admin Page Creation | 333140 , 341266 |
| CVE-2017-14955 | Check_MK 1.2.8p25 - Information Disclosure | 330791 , 340152 |
| CVE-2025-49493 | Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE) | 344372 |
| CVE-2026-48053 | Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset | 337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022 |
| CVE-2026-86159 | SourceCodester Online Voting System ajax.php save_user sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-86160 | SourceCodester Online Voting System ajax.php delete_voting sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-86161 | SourceCodester Online Voting System ajax.php delete_category sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122 |
| CVE-2026-86162 | SourceCodester Online Voting System ajax.php login sql injection | 340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122 |
| CVE-2026-86168 | code-projects Content Management System login.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2023-40355 | Axigen WebMail - Cross-Site Scripting | 346755 |
| CVE-2025-2610 | MagnusBilling Alarm Module - Cross-Site Scripting | 333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148 |
| CVE-2021-22017 | vCenter Server - Improper Access Control | 344370 |
| CVE-2026-19956 | gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-side request forgery | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2022-50961 | WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS | 333140 , 333141 , 340095 , 340147 , 340148 , 346755 |
| CVE-2026-68583 | luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name | 333140 , 333141 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-72747 | AVideo Stored Cross-Site Scripting via Unauthenticated Registration | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-72821 | Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86197 | Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2023-27624 | WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS | 346755 |
| CVE-2024-50857 | GestioIP - Reflected Cross-Site Scripting | 340147 , 340148 , 341256 , 341266 , 342259 , 346755 |
| CVE-2026-79663 | Ech0 before 4.7.3 Stored XSS via RSS feed tag names | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-33534 | EspoCRM <= 9.3.3 - Server-Side Request Forgery | 398003 |
| CVE-2024-55550 | Mitel MiCollab - Arbitary File Read | 340007 , 341256 , 344360 , 350147 , 390709 |
| CVE-2026-66300 | SNOMED International Snowstorm reflected XSS | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-86163 | itsourcecode Sales and Inventory System pro_del.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86164 | itsourcecode Sales and Inventory System trans_view.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-86170 | DefaultFuction CRM edit.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-9608 | QianFox FoxCMS Administrator Backend edit cross site scripting | 340095 , 346755 |