Atomicorp WAF Research Notes
Research Update - 2026-09-13
Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.
The entries published in this update represent research notes produced during ongoing analysis activities.
These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.
Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.
Presence means a positive research finding was published. Absence means no conclusion should be drawn.
CVE Notes Published in This Update
| CVE | Vulnerability Name | Rules Observed |
|---|---|---|
| CVE-2026-90770 | Spug through 3.4.0 Remote Code Execution via ping_check | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90769 | Open Notebook before 1.11.0 Server-Side Request Forgery via link-source | 337109 , 337110 , 344360 , 398021 , 398022 |
| CVE-2026-90603 | Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload | 351000 |
| CVE-2026-36989 | LuxCal Web Calendar SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90514 | SourceCodester School Registration and Fee System save_stud.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90515 | SourceCodester School Registration and Fee System delete_stud.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90516 | SourceCodester School Registration and Fee System pay_report.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90526 | SourceCodester School Registration and Fee System save_class.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90527 | quequnlong shiyi-blog Add Message API index.vue cross site scripting | 333140 |
| CVE-2026-90571 | Exrick xmall Order Printing order-print.jsp cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90528 | TDuckApp tduck-platform Form Write View index.vue cross site scripting | 333140 , 333141 , 340095 , 342259 |
| CVE-2026-90529 | DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting | 333140 , 340095 , 340147 , 341256 , 342259 , 346755 |
| CVE-2026-90563 | maliangnansheng bbs-springboot ArticleController.java utils.toToc cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90564 | quequnlong shiyi-blog chat sendMsg Endpoint index.vue SysChatMsgMapper.getChatMsgList cross site scripting | 333140 |
| CVE-2026-90567 | quequnlong shiyi-blog Search index.vue highlightKeyword cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90568 | moxi624 Mogu Blog v2 blogSort Endpoint info.ftl BlogSortServiceImpl.addBlogSort cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90602 | Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |
| CVE-2020-15875 | LibreNMS SQL Injection Vulnerability | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90569 | linlinjava litemall Admin Topic index.vue AdminTopicController.validate cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90570 | linlinjava litemall Product Detail index.vue AdminGoodsService.validate cross site scripting | 333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148 |
| CVE-2026-90575 | PHPGurukul Small CRM Login Success login.php unserialize deserialization | 340014 , 340193 , 344362 , 344363 , 344365 , 344370 , 344380 , 344382 , 344385 , 360152 , 390613 , 390614 , 390722 |
| CVE-2026-90488 | Xuxueli xxl-job GlueFactory.java GroovyClassLoader.parseClass code injection | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2026-90500 | lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload | 351000 |
| CVE-2026-90511 | GongShengyue OnlineBooks listSplit BooksServlet.java sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90525 | itsourcecode Sales and Inventory System cust_pos_trans.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90574 | itsourcecode Sales and Inventory System emp_transac.php add sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90580 | FlowiseAI Flowise Evaluations Endpoint index.ts axios.post server-side request forgery | 390719 |
| CVE-2026-90581 | cym1102 nginxWebUI autoUpdate MainController.autoUpdate code injection | 340014 , 340023 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 393655 |
| CVE-2026-90597 | itsourcecode Sales and Inventory System sup_edit1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90600 | itsourcecode Sales and Inventory System inv_edit1.php sql injection | 340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572 |
| CVE-2026-90489 | Xuxueli xxl-job insert cross site scripting | 333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148 |