Atomicorp WAF Research Notes

Research Update - 2026-09-12

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-72710SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655
CVE-2026-89249AVideo YPTWallet Stored XSS via CryptoWallet Configuration333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-89253AVideo Stored XSS via donationLink in watch page button333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-89254AVideo CustomizeUser Stored XSS via field_name Parameter333140 , 333141 , 340095 , 340147 , 341256 , 342259 , 346755
CVE-2026-89255AVideo LoginControl Stored XSS via PGP Public Key333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-89256AVideo Bookmark Plugin Stored XSS via Chapter Names333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-89243WWBN AVideo Stored XSS via UserGroups setGroup_name333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-72708SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-89250WWBN AVideo Unauthenticated File Read via getRecordedFile.php340007 , 344360 , 347009 , 390709
CVE-2025-57231Path Traversal in avatar attachments in Docmost v0.21.0 Vulnerability340007 , 344360 , 347009 , 390709
CVE-2026-54166Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-89242WWBN AVideo Unauthenticated SSRF via login.json.php337109 , 337110 , 398022
CVE-2026-36392FairSketch Rise CRM Version 3.9.6 Cross-Site Scripting Vulnerability333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755
CVE-2026-89240WWBN AVideo Reflected XSS via confirmLivePassword.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-89241WWBN AVideo Reflected XSS via confirmLivePassword.php333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-89244WWBN AVideo Reflected XSS via Gallery Category getBackURL333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-89247WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php330791 , 340152 , 341256 , 344360 , 344370 , 344372 , 344373 , 347009 , 350147 , 380018
CVE-2026-89148AVideo Open Redirect via playlistSort.php Referer Header340162 , 340163 , 340165 , 344365