Atomicorp WAF Research Notes

Research Update - 2026-09-18

Atomicorp WAF Research Notes document selected engineering observations, testing results, attack-pattern analysis, and WAF rule interactions.

The entries published in this update represent research notes produced during ongoing analysis activities.

These notes are not intended to represent the full set of vulnerabilities mitigated by Atomicorp products and should not be interpreted as a coverage matrix, certification list, or census of protected CVEs.

Atomicorp WAF protections are primarily designed around attack techniques and exploit behaviors rather than individual vulnerability identifiers. A published research note documents a positive research finding related to that CVE. If a CVE is absent from these notes, no conclusion should be drawn about protection status.

Presence means a positive research finding was published. Absence means no conclusion should be drawn.

CVE Notes Published in This Update

CVEVulnerability NameRules Observed
CVE-2026-85688TEN Framework - Arbitrary File Read & Write344360 , 390709
CVE-2026-54670WeGIA: Unauthenticated Auth Bypass + Local File Inclusion340007 , 344360 , 390709
CVE-2026-45143Chamilo LMS: Student-to-admin stored XSS in private messages via v-html333140
CVE-2026-47252Anyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari)340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-63459Vendure: Stored XSS in the Admin Dashboard via unsafe HTML-stripping (innerHTML) of entity descriptions333140 , 333141
CVE-2026-92970HUBzero CMS through 2.2.32 Path Traversal via File Upload340007 , 344360 , 390709
CVE-2026-92985SiYuan before 3.8.4 Cross-Site Scripting via Bookmark Labels333140 , 333141 , 334168 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-92986SiYuan before 3.8.4 Cross-Site Scripting via Document Title333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-54507Vvveb oEmbedProxy vulnerable to server-side request forgery337109 , 337110 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-93292SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-93426SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-54597ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Parameter340016 , 340017 , 340144 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380122
CVE-2026-54253TS3 Manager: Reflected XSS via /api/download port parameter steals operator session333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-54354MapServer: PostGIS Numeric Filter Value SQL Injection in MapServer Runtime Query Translation340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-54596ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-53557SQLBot: Second-Order SQL Injection via Excel Datasource Leading to Remote Command Execution340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-54339Glean: Server-Side Request Forgery (SSRF) with Full Response Disclosure via Malicious RSS Feed in /api/feeds/discover337109 , 337110 , 344360 , 398021 , 398022
CVE-2026-54506Vvveb: Stored XSS via sanitizeHTML() bypass in user profile bio field333140 , 333141 , 340095 , 340147 , 340148 , 340247 , 340248 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-53534JabRef CAYW Sublime Text integration permits operating-system command injection340014 , 340029 , 340193 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 347009 , 390904 , 393655
CVE-2026-53554SQLBot: Arbitrary File Write via parseExcel Leading to Code Execution Through Alembic Import Processing340014 , 340023 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655
CVE-2026-54646CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 380026 , 380122 , 390572
CVE-2026-54647CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-92919admin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload Filename340007 , 344360 , 390709
CVE-2026-93014RosarioSIS before 12.9 Path Traversal in File Deletion via filename Parameter344360 , 347009 , 390709
CVE-2026-61793Nuxt OG Image has unauthenticated SSRF via fonts[].path URL parameter337109 , 337110 , 340162 , 340163 , 340165 , 344360 , 347009 , 390722 , 398021 , 398022
CVE-2026-17576InfiniteWP Client <= 1.13.9 - Authenticated (Admin+) SQL Injection via 'iwp_get_comments_*' Array Key340017 , 340144 , 340156 , 360147 , 360148 , 380122
CVE-2026-51133za-internet GmbH C-MOR Video Surveillance <= V6.0104 Arbitrary Code Execution Vulnerability333140 , 333141 , 340087 , 340095 , 340099 , 340147 , 340148 , 341099 , 341256 , 341266 , 342259 , 346755 , 350147 , 350148
CVE-2026-53556SQLBot: Authenticated SQL Injection in previewData Resulting in Arbitrary File Read340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-92926code-projects Matrimonial System partner_preference.php writepartnerprefs sql injection340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-54613Vvveb: Path Traversal in Revision Backup Reader/Deleter via Unsanitized theme Parameter344360 , 347009
CVE-2026-53555Stored XSS via SVG Upload333140 , 333141 , 340095 , 340147 , 340148 , 341256 , 342259 , 346755 , 350147 , 350148
CVE-2026-56281Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint340016 , 340017 , 340144 , 340145 , 340156 , 340157 , 341145 , 341245 , 360147 , 360148 , 380026 , 380122 , 390572
CVE-2026-54546CloudTAK: Authenticated full-read SSRF in CloudTAK basemap import (PUT /api/basemap) — no IP-classification guard337109 , 337110 , 340162 , 340163 , 344360 , 398021 , 398022
CVE-2026-54645CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass333140 , 333141
CVE-2026-92993Dromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injection340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655