Atomicorp WAF Research Notes
Research Update - 2026-09-12
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-72710 | SPIP < 4.4.18 Remote Code Execution via editer_objet.php Job Queue Injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-89249 | AVideo YPTWallet Stored XSS via CryptoWallet Configuration | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-89253 | AVideo Stored XSS via donationLink in watch page button | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-89254 | AVideo CustomizeUser Stored XSS via field_name Parameter | 333140 , 333141 , 340095 , 340147 , 341256 , 342259 , 346755 |
| CVE-2026-89255 | AVideo LoginControl Stored XSS via PGP Public Key | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-89256 | AVideo Bookmark Plugin Stored XSS via Chapter Names | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-89243 | WWBN AVideo Stored XSS via UserGroups setGroup_name | 333140 , 333141 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-72708 | SPIP < 4.4.18 Unauthenticated SQL Injection via sitemap annee Parameter | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-89250 | WWBN AVideo Unauthenticated File Read via getRecordedFile.php | 340007 , 344360 , 347009 , 390709 |
| CVE-2025-57231 | Path Traversal in avatar attachments in Docmost v0.21.0 Vulnerability | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-54166 | Shelf Vulnerable to Server-Side Request Forgery (SSRF) via Asset CSV Import imageUrl Validation Bypass | 337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022 |
| CVE-2026-89242 | WWBN AVideo Unauthenticated SSRF via login.json.php | 337109 , 337110 , 398022 |
| CVE-2026-36392 | FairSketch Rise CRM Version 3.9.6 Cross-Site Scripting Vulnerability | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 |
| CVE-2026-89240 | WWBN AVideo Reflected XSS via confirmLivePassword.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-89241 | WWBN AVideo Reflected XSS via confirmLivePassword.php | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-89244 | WWBN AVideo Reflected XSS via Gallery Category getBackURL | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-89247 | WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php | 330791 , 340152 , 341256 , 344360 , 344370 , 344372 , 344373 , 347009 , 350147 , 380018 |
| CVE-2026-89148 | AVideo Open Redirect via playlistSort.php Referer Header | 340162 , 340163 , 340165 , 344365 |