Atomicorp WAF Research Notes

Research Update - 2026-09-06

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2022-22947Spring Cloud Gateway Code Injection344370 , 393655
CVE-2024-46506NetAlertX 23.01.14–24.x < 24.10.12 - Remote Code Execution392301 , 392648
CVE-2026-72876Dokploy: Cross-organization IDOR leads to root RCE on another tenant's server via swarm.*340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2015-7501Red Hat JBoss - Insecure Deserialization344380
CVE-2018-1217Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control391213
CVE-2018-12463Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection330791 , 340152
CVE-2018-6530D-Link - Unauthenticated Remote Code Execution330791 , 340152 , 344363
CVE-2018-7600Drupal - Remote Code Execution330791 , 340152
CVE-2019-11580Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution391213
CVE-2019-17506D-Link DIR-868L/817LW - Information Disclosure330791 , 340152
CVE-2019-7194QNAP Photo Station < 6.0.3 - Remote Code Execution340128 , 380018 , 380026 , 390801
CVE-2019-7238Sonatype Nexus Repository Manager <3.15.0 - Remote Code Execution344360 , 344363 , 344370
CVE-2019-9670Synacor Zimbra Collaboration <8.7.11p10 - XML External Entity Injection344372
CVE-2020-11975Apache Unomi - Remote Code Execution337210
CVE-2020-15505MobileIron Core & Connector <= v10.6 & Sentry <= v9.8 - Remote Code Execution391213
CVE-2021-21978VMware View Planner <4.6 SP1- Remote Code Execution330791 , 340007 , 340152
CVE-2021-3378FortiLogger 4.4.2.2 - Arbitrary File Upload330791 , 340152
CVE-2022-31181PrestaShop - SQL Injection to Eval Injection340157 , 340159 , 341245 , 344362 , 360147 , 360148 , 390704
CVE-2022-3980Sophos Mobile managed on-premises - XML External Entity Injection344372
CVE-2023-20887VMware VRealize Network Insight - Remote Code Execution391213
CVE-2023-2648Weaver E-Office 9.5 - Remote Code Execution330791 , 340152
CVE-2023-4450JeecgBoot JimuReport - Template injection340014 , 344370 , 393655
CVE-2023-47248PyArrow Flight RPC - Remote Code Execution391213
CVE-2024-0799Arcserve Unified Data Protection - Authentication Bypass391213
CVE-2024-27348Apache HugeGraph-Server - Remote Command Execution380026
CVE-2024-43965SendGrid for WordPress <= 1.4 - SQL Injection380122
CVE-2024-55956Cleo Harmony < 5.8.0.24 - File Upload Vulnerability391213
CVE-2024-7314AJ-Report < 1.4.1 - Remote Code Execution337209 , 337211 , 380026
CVE-2024-8353GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object Injection340014 , 344370
CVE-2025-2776SysAid On-Prem <= 23.3.40 - XML External Entity330791 , 340152 , 344372
CVE-2025-2777SysAid On-Prem <= 23.3.40 - XML External Entity330791 , 340152 , 344372
CVE-2025-54123Hoverfly <= 1.11.3 - Remote Code Execution344360
CVE-2025-58360GeoServer - XML External Entity Injection391213
CVE-2025-61882Oracle E-Business Suite 12.2.3–12.2.14 – Remote Code Execution391213
CVE-2025-66516Apache Tika - XML External Entity Injection391213
CVE-2026-0770Langflow < 1.3.0 - Remote Code Execution via validate_code() exec()344360 , 344370
CVE-2026-39394CI4MS has an .env CRLF Injection via Unvalidated host Parameter in Install Controller340007 , 344360 , 347009
CVE-2026-25512Group-Office < 26.0.5 - Remote Code Execution344363
CVE-2026-66398phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-77086SiYuan before v3.7.4 Path Traversal via packageName340007 , 344360 , 347009 , 390709
CVE-2026-86123SQL Chat Unauthenticated Database-Connection Proxy in the /api/connection Endpoints337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-66396SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-86189WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php340007 , 344360 , 390709
CVE-2024-9465Palo Alto Expedition - SQL Injection340016 , 341245 , 380026 , 380122
CVE-2026-27971Qwik - Unauthenticated RCE via server$ Deserialization391213
CVE-2026-86119Webstudio through 0.296.0 SSRF via /cgi proxy routes337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2021-21351XStream <1.4.16 - Remote Code Execution344380
CVE-2022-31678VMWare Cloud Foundation NSX-V - XML External Entity (XXE)344372
CVE-2024-4180The Events Calendar < 6.4.0.1 - Cross-site Scripting346755
CVE-2026-41042Apache Gravitino < 1.2.1 - Unauthenticated Remote Code Execution344370
CVE-2025-48703CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution330791 , 340152
CVE-2019-25745WordPress Plugin Google Review Slider 6.1 SQL Injection via tid340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2021-25646Apache Druid - Remote Code Execution337209 , 337210 , 337211 , 340095 , 344360 , 344361 , 344370 , 380026
CVE-2025-11307WP Google Maps < 9.0.48 - Cross-Site Scripting346755
CVE-2026-40466Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypass330925 , 340162 , 340163
CVE-2026-5027Langflow <= 1.8.4 - Path Traversal to RCE via File Upload300008
CVE-2024-50334Scoold < 1.64.0 - Authentication Bypass391213
CVE-2026-39352Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path Traversal340007 , 340029 , 344360 , 344370 , 390709
CVE-2026-67281Unauthenticated file read in Mikrotik RouterOS340007 , 344360 , 347009 , 390709
CVE-2026-70492Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages333140 , 333141 , 340147 , 340148 , 341256 , 346755
CVE-2026-75574Grav before 4.2.2 Remote Code Execution via Email Twig340014 , 344361 , 344363 , 344364 , 344366 , 344370
CVE-2025-64328FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command Injection344364
CVE-2026-34605SiYuan Note - Cross-Site Scripting300013
CVE-2026-84196Kyverno before 1.18.0 Server-Side Request Forgery via apiCall337109 , 337110 , 344360 , 398021 , 398022
CVE-2025-6204DELMIA Apriso - Command Injection340095 , 341245 , 344361 , 344365 , 344366 , 347019 , 390724
CVE-2011-3600Apache OFBiz - XML External Entity Injection344372
CVE-2017-17762Episerver 7 - Blind XML External Entity Injection344372
CVE-2019-11253Kubernetes API Server - YAML Parsing DoS (Billion Laughs)391213
CVE-2019-13608Citrix StoreFront Server - XML External Entity344372 , 391213
CVE-2019-8086Adobe Experience Manager - XML External Entity Injection330925
CVE-2019-9621Zimbra Collaboration Suite - SSRF344372
CVE-2020-11991Apache Cocoon 2.1.12 - XML Injection344372
CVE-2022-2414FreeIPA - XML Entity Injection344372
CVE-2024-38653Ivanti Avalanche SmartDeviceServer - XML External Entity330791 , 340152
CVE-2025-2221WordPress WPCOM Member <= 1.7.6 - SQL Injection340016 , 380122
CVE-2025-2775SysAid On-Prem <= 23.3.40 - XML External Entity330791 , 340152 , 344372
CVE-2026-50151oras-go: credential forwarding via unvalidated Location header in blob upload390719
CVE-2023-42344OpenCMS - XML external entity (XXE)330791 , 340152 , 344372
CVE-2019-2616Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection330791 , 340152
CVE-2023-46818ISPConfig - PHP Code Injection340095
CVE-2024-38288TurboMeeting - Post-Authentication Command Injection344363 , 344370
CVE-2024-8625WordPress TS Poll < 2.4.0 - SQL Injection380122
CVE-2026-28409WeGIA <= 3.6.4 - Remote Code Execution344363 , 390700 , 393655
CVE-2024-13352Legull WordPress - Cross-Site Scripting341266 , 346755
CVE-2024-13625Tube Video Ads Lite - Reflected XSS341266
CVE-2024-5082Nexus Repository 2 - Remote Code Execution330791 , 340152
CVE-2026-82246Budibase Server before 3.41.3 SSRF via Query Import337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-79781rclone serve s3 Path Traversal via dot-dot object keys340007 , 344360 , 347009 , 390709
CVE-2026-82233SiYuan before v3.8.1 Path Traversal via asset.upload340007 , 344360 , 390709
CVE-2026-86188AVideo YPTSocket Plugin Unauthenticated Cross-Site Scripting333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-66472XWiki DeleteApplication - Cross-Site Scripting346755
CVE-2026-54020Open WebUI: DNS Rebinding SSRF Bypass337109 , 337110 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-72814actix-web before 0.6.10 Information Disclosure via Files340007 , 344360 , 347009 , 390709
CVE-2016-10976Safe Editor Plugin < 1.2 - CSS/JS-injection346755
CVE-2018-10141Palo Alto Networks PAN-OS GlobalProtect <8.1.4 - Cross-Site Scripting346755
CVE-2018-11133Quest KACE SMA /common/run_cross_report.php 'fmt' XSS346755
CVE-2019-14750osTicket < 1.12.1 - Cross-Site Scripting346755
CVE-2019-17231WordPress OneTone theme <= 3.0.6 – Unauthenticated Stored XSS346755
CVE-2019-9955Zyxel - Cross-Site Scripting346755
CVE-2020-14408Agentejo Cockpit 0.10.2 - Cross-Site Scripting346755
CVE-2020-15895D-Link DIR-816L 2.x - Cross-Site Scripting346755
CVE-2020-23814XXL-JOB v2.2.0 — Stored Cross Site Scripting333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2020-9036Jeedom <=4.0.38 - Cross-Site Scripting346755
CVE-2021-22122FortiWeb - Cross Site Scripting346755
CVE-2021-24351WordPress The Plus Addons for Elementor <4.1.12 - Cross-Site Scripting346755
CVE-2021-24878SupportCandy < 2.2.7 - Reflected Cross-Site Scripting346755
CVE-2021-26812Moodle Jitsi Meet 2.7-2.8.3 - Cross-Site Scripting346755
CVE-2021-27909Mautic <3.3.4 - Cross-Site Scripting346755
CVE-2021-30151Sidekiq <=6.2.0 - Cross-Site Scripting346755
CVE-2021-33829Drupal 7 CKEditor XSS333141
CVE-2021-40968Spotweb <= 1.5.1 - Cross Site Scripting346755
CVE-2021-40969Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)346755
CVE-2021-40970Spotweb <= 1.5.1 - Cross Site Scripting346755
CVE-2021-40971Spotweb <= 1.5.1 - Cross Site Scripting346755
CVE-2021-40972Spotweb <= 1.5.1 - Cross Site Scripting346755
CVE-2021-40973Spotweb <= 1.5.1 - Cross Site Scripting346755
CVE-2021-41174Grafana 8.0.0 <= v.8.2.2 - Angularjs Rendering Cross-Site Scripting346755
CVE-2021-42063SAP Knowledge Warehouse <=7.5.0 - Cross-Site Scripting346755
CVE-2021-42566myfactory FMS - Cross-Site Scripting346755
CVE-2022-1597WordPress WPQA <5.4 - Cross-Site Scripting346755
CVE-2022-1916WordPress Active Products Tables for WooCommerce <1.0.5 - Cross-Site Scripting346755
CVE-2022-2627WordPress Newspaper < 12 - Cross-Site Scripting346755
CVE-2022-29548WSO2 - Cross-Site Scripting346755
CVE-2022-45365Stock Ticker <= 3.23.2 - Cross-Site-Scripting346755
CVE-2023-29506XWiki >= 13.10.8 - Cross-Site Scripting346755
CVE-2023-40208Stock Ticker <= 3.23.2 - Cross-Site Scripting346755
CVE-2023-44813mooSocial v.3.1.8 - Cross-Site Scripting346755
CVE-2024-12724WP DeskLite - Reflected XSS340148 , 341266 , 346755
CVE-2024-13222WordPress User Messages <= 1.2.4 - Reflected XSS341266 , 346755 , 390585
CVE-2024-13328Giga Messenger WordPress - Cross-Site Scripting341266 , 346755
CVE-2024-28623RiteCMS 3.0.0 - Cross-site Scripting346755 , 380026
CVE-2024-35627TileServer API - Cross Site Scripting346755
CVE-2024-42852AcuToWeb server/10.5.0.7577c8b - Cross-Site Scripting346755
CVE-2025-51501Microweber CMS2.0 - Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2025-51502Microweber CMS 2.0 - Reflected XSS in Admin Page Creation333140 , 341266
CVE-2017-14955Check_MK 1.2.8p25 - Information Disclosure330791 , 340152
CVE-2025-49493Akamai CloudTest < 60 2025.06.02 - XML External Entity (XXE)344372
CVE-2026-48053Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-86159SourceCodester Online Voting System ajax.php save_user sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-86160SourceCodester Online Voting System ajax.php delete_voting sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-86161SourceCodester Online Voting System ajax.php delete_category sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-86162SourceCodester Online Voting System ajax.php login sql injection340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 360147 , 360148 , 380122
CVE-2026-86168code-projects Content Management System login.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2023-40355Axigen WebMail - Cross-Site Scripting346755
CVE-2025-2610MagnusBilling Alarm Module - Cross-Site Scripting333141 , 340147 , 340148 , 341256 , 342259 , 346755 , 350148
CVE-2021-22017vCenter Server - Improper Access Control344370
CVE-2026-19956gomarble-ai facebook-ads-mcp-server server.py fetch_pagination_url server-side request forgery337109 , 337110 , 344360 , 398021 , 398022
CVE-2022-50961WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS333140 , 333141 , 340095 , 340147 , 340148 , 346755
CVE-2026-68583luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name333140 , 333141 , 340147 , 340148 , 342259 , 346755 , 350147 , 350148
CVE-2026-72747AVideo Stored Cross-Site Scripting via Unauthenticated Registration333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72821Grav Form Plugin before 9.1.15 Stored XSS via Radio Toggle333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-86197Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2023-27624WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS346755
CVE-2024-50857GestioIP - Reflected Cross-Site Scripting340147 , 340148 , 341256 , 341266 , 342259 , 346755
CVE-2026-79663Ech0 before 4.7.3 Stored XSS via RSS feed tag names333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-33534EspoCRM <= 9.3.3 - Server-Side Request Forgery398003
CVE-2024-55550Mitel MiCollab - Arbitary File Read340007 , 341256 , 344360 , 350147 , 390709
CVE-2026-66300SNOMED International Snowstorm reflected XSS333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-86163itsourcecode Sales and Inventory System pro_del.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86164itsourcecode Sales and Inventory System trans_view.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-86170DefaultFuction CRM edit.php sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-9608QianFox FoxCMS Administrator Backend edit cross site scripting340095 , 346755